IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe deserialization in Java. By sending specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 182396.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Maximo_asset_management | Ibm | 7.6.0 (including) | 7.6.0.10 (excluding) |
Maximo_asset_management | Ibm | 7.6.1 (including) | 7.6.1.2 (excluding) |