IBM Maximo Asset Management
cpe:2.3:a:ibm:maximo_asset_management:*:*:*:*:*:*:*
- 7.6.1.3
A vulnerability allowing unrestricted file uploads has been identified in the IBM Maximo Asset Management 7.6.1.3 MXAPIASSET API. This issue allows authenticated users with low privileges to upload restricted file types by simply adding a dot at the end of the file name, but only when Maximo is installed on a Windows operating system.
Exploitation of this vulnerability could lead to unauthorized file uploads, potentially allowing for the execution of malicious files or scripts on the server.
Users can upgrade to IBM Maximo Asset Management 7.6.1.3 iFix 7.6.1.3-TIV-MBS-IF015. Instructions for downloading this fix are available on the IBM Support Fix Central website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.