CVE-2014-0893: IBM Maximo Asset Management
Medium severity, CVSS 4.3. EPSS: 1.1% chance of exploitation in the next 30 days.
Cross-site scripting (XSS) vulnerability in customreport.jsp in IBM Maximo Asset Management 7.5.x before 7.5.0.5 IFIX006 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified parameters.
Affected products
- IBM Maximo Asset Management: version 7.5.0.0 only; version 7.5.0.1 only; version 7.5.0.2 only; version 7.5.0.3 only; version 7.5.0.4 only; version 7.5.0.5 only
- IBM Smartcloud Control Desk: version 7.0 only; version 7.5 only; version 7.5.0.0 only; version 7.5.0.1 only; version 7.5.0.2 only; version 7.5.0.3 only; …
Published 2014-05-26. Last modified 2026-06-17.