CVE Vulnerabilities

CVE-2019-4266

Improper Privilege Management

Published: May 06, 2020 | Modified: May 08, 2020
CVSS 3.x
2.4
LOW
Source:
NVD
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

IBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 does not have device jailbreak detection which could result in an attacker gaining sensitive information about the device. IBM X-Force ID: 160199.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Maximo_anywhere Ibm 7.6.2.0 (including) 7.6.2.0 (including)
Maximo_anywhere Ibm 7.6.2.1 (including) 7.6.2.1 (including)
Maximo_anywhere Ibm 7.6.3.0 (including) 7.6.3.0 (including)
Maximo_anywhere Ibm 7.6.3.1 (including) 7.6.3.1 (including)

Potential Mitigations

References