PublicCVE

CVE-2021-20509

HIGH7.0JSON exportCreate alert

Description

IBM Maximo Asset Management 7.6.0 and 7.6.1 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 198243.

CVSS breakdown

CVSS 3.0
Integrity
High
Attack Complexity
High
Scope
Unchanged
Availability
High
User Interaction
Required
Attack Vector
Local
Privileges Required
None
Confidentiality
High
RC
Changed
RL
O
E
Unchanged

Affected products