IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to conduct phishing attacks, using a tabnabbing attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 179537.
A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect. This simplifies phishing attacks.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Control_desk | Ibm | 7.6.1 (including) | 7.6.1 (including) |
Control_desk | Ibm | 7.6.1.1 (including) | 7.6.1.1 (including) |
Maximo_asset_configuration_manager | Ibm | 7.6.6 (including) | 7.6.6 (including) |
Maximo_asset_configuration_manager | Ibm | 7.6.7 (including) | 7.6.7 (including) |
Maximo_asset_configuration_manager | Ibm | 7.6.7.1 (including) | 7.6.7.1 (including) |
Maximo_asset_health_insights | Ibm | 7.6.1 (including) | 7.6.1 (including) |
Maximo_asset_health_insights | Ibm | 7.6.1.1 (including) | 7.6.1.1 (including) |
Maximo_asset_management | Ibm | * | 7.6.1.2 (excluding) |
Maximo_asset_management_scheduler | Ibm | 7.6.7 (including) | 7.6.7 (including) |
Maximo_asset_management_scheduler | Ibm | 7.6.7.1 (including) | 7.6.7.1 (including) |
Maximo_asset_management_scheduler | Ibm | 7.6.7.3 (including) | 7.6.7.3 (including) |
Maximo_asset_management_scheduler_plus | Ibm | 7.6.7 (including) | 7.6.7 (including) |
Maximo_asset_management_scheduler_plus | Ibm | 7.6.7.1 (including) | 7.6.7.1 (including) |
Maximo_asset_management_scheduler_plus | Ibm | 7.6.7.3 (including) | 7.6.7.3 (including) |
Maximo_calibration | Ibm | 7.6 (including) | 7.6 (including) |
Maximo_enterprise_adapter | Ibm | 7.6 (including) | 7.6 (including) |
Maximo_enterprise_adapter | Ibm | 7.6.1 (including) | 7.6.1 (including) |
Maximo_equipment_maintenance_assistant | Ibm | - (including) | - (including) |
Maximo_for_aviation | Ibm | 7.6.6 (including) | 7.6.6 (including) |
Maximo_for_aviation | Ibm | 7.6.7 (including) | 7.6.7 (including) |
Maximo_for_aviation | Ibm | 7.6.8 (including) | 7.6.8 (including) |
Maximo_for_life_sciences | Ibm | 7.6 (including) | 7.6 (including) |
Maximo_for_nuclear_power | Ibm | 7.6.1 (including) | 7.6.1 (including) |
Maximo_for_oil_and_gas | Ibm | 7.6.1 (including) | 7.6.1 (including) |
Maximo_for_service_providers | Ibm | 7.6.3.1 (including) | 7.6.3.1 (including) |
Maximo_for_service_providers | Ibm | 7.6.3.2 (including) | 7.6.3.2 (including) |
Maximo_for_service_providers | Ibm | 7.6.3.3 (including) | 7.6.3.3 (including) |
Maximo_for_transportation | Ibm | 7.6.2.3 (including) | 7.6.2.3 (including) |
Maximo_for_transportation | Ibm | 7.6.2.4 (including) | 7.6.2.4 (including) |
Maximo_for_transportation | Ibm | 7.6.2.5 (including) | 7.6.2.5 (including) |
Maximo_for_utilities | Ibm | 7.6.0.1 (including) | 7.6.0.1 (including) |
Maximo_for_utilities | Ibm | 7.6.0.2 (including) | 7.6.0.2 (including) |
Maximo_linear_asset_manager | Ibm | 7.6.0 (including) | 7.6.0 (including) |
Maximo_linear_asset_manager | Ibm | 7.6.0.2 (including) | 7.6.0.2 (including) |
Maximo_linear_asset_manager | Ibm | 7.6.0.3 (including) | 7.6.0.3 (including) |
Maximo_network_on_blockchain | Ibm | 7.6.0.0 (including) | 7.6.0.0 (including) |
Maximo_network_on_blockchain | Ibm | 7.6.0.1 (including) | 7.6.0.1 (including) |
Maximo_spatial_asset_management | Ibm | 7.6.0.2 (including) | 7.6.0.2 (including) |
Maximo_spatial_asset_management | Ibm | 7.6.0.3 (including) | 7.6.0.3 (including) |
Maximo_spatial_asset_management | Ibm | 7.6.0.4 (including) | 7.6.0.4 (including) |
Maximo_spatial_asset_management | Ibm | 7.6.0.5 (including) | 7.6.0.5 (including) |
Tivoli_integration_composer | Ibm | 7.6 (including) | 7.6 (including) |