Description
IBM Maximo Asset Management 7.6.1.3 MXAPIASSET API is vulnerable to unrestricted file upload which allows authenticated low privileged user to upload restricted file types with a simple method of adding a dot to the end of the file name if Maximo is installed on Windows operating system.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-41333 | IBM Maximo Asset Management 7.6.1.3 MXAPIASSET API is vulnerable to unrestricted file upload which allows authenticated low privileged user to upload restricted file types with a simple method of adding a dot to the end of the file name if Maximo is installed on Windows operating system. |
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7174819 |
|
History
Wed, 12 Feb 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 24 Jan 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Maximo Asset Management 7.6.1.3 MXAPIASSET API is vulnerable to unrestricted file upload which allows authenticated low privileged user to upload restricted file types with a simple method of adding a dot to the end of the file name if Maximo is installed on Windows operating system. | |
| Title | IBM Maximo Asset Management file upload | |
| First Time appeared |
Ibm
Ibm maximo Asset Management |
|
| Weaknesses | CWE-98 | |
| CPEs | cpe:2.3:a:ibm:maximo_asset_management:7.6.1.3:*:*:*:*:*:*:* | |
| Vendors & Products |
Ibm
Ibm maximo Asset Management |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-02-12T20:01:19.525Z
Reserved: 2024-08-21T19:10:49.905Z
Link: CVE-2024-45077
Updated: 2025-02-12T19:55:54.038Z
Status : Analyzed
Published: 2025-01-24T16:15:36.903
Modified: 2025-08-14T15:18:56.307
Link: CVE-2024-45077
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD