PublicCVE

CVE-2018-2028

MEDIUM6.5JSON exportCreate alert

Description

IBM Maximo Asset Management 7.6 could allow a an authenticated user to replace a target page with a phishing site which could allow the attacker to obtain highly sensitive information. IBM X-Force ID: 155554.

CVSS breakdown

CVSS 3.0
Availability
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Attack Complexity
Low
Privileges Required
Low
Integrity
None
Attack Vector
Network
RC
Changed
E
Unchanged
RL
O

Affected products