← Back

CVE-2020-4409

nvd nist
Published: Sep 16, 2020Modified: Jun 17, 2026

JSON object

Loading...
8.2
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Exploitability: 2.8 / Impact: 4.7
Source: NVD

Description

IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to conduct phishing attacks, using a tabnabbing attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 179537.

Affected (42)

20 products
Control Desk
Maximo Asset Health Insights
Maximo Asset Management
Maximo Asset Management Scheduler
Maximo Calibration
Maximo Enterprise Adapter
Maximo For Aviation
Maximo For Life Sciences
Maximo For Nuclear Power
Maximo For Oil And Gas
Maximo For Service Providers
Maximo For Transportation
Maximo For Utilities
Maximo Linear Asset Manager
Maximo Network On Blockchain
Maximo Spatial Asset Management
Tivoli Integration Composer
Configuration A
42 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
Version 7.6.1.1
Version 7.6.1
Ibm
Version 7.6.6
Version 7.6.7.1
Version 7.6.7
Ibm
Version 7.6.1.1
Version 7.6.1
Before 7.6.1.2
Ibm
Version 7.6.7.1
Version 7.6.7.3
Version 7.6.7
Ibm
Version 7.6.7.1
Version 7.6.7.3
Version 7.6.7
Version 7.6
Ibm
Version 7.6.1
Version 7.6
All versions
Ibm
Version 7.6.6
Version 7.6.7
Version 7.6.8
Version 7.6
Version 7.6.1
Version 7.6.1
Ibm
Version 7.6.3.1
Version 7.6.3.2
Version 7.6.3.3
Ibm
Version 7.6.2.3
Version 7.6.2.4
Version 7.6.2.5
Ibm
Version 7.6.0.1
Version 7.6.0.2
Ibm
Version 7.6.0.2
Version 7.6.0.3
Version 7.6.0
Ibm
Version 7.6.0.0
Version 7.6.0.1
Ibm
Version 7.6.0.2
Version 7.6.0.3
Version 7.6.0.4
Version 7.6.0.5
Version 7.6

References (4)

Source: psirt@us.ibm.com
VDB EntryVendor Advisory
Source: psirt@us.ibm.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
VDB EntryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.