CVE-2019-4591: IBM Maximo Asset Management
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
IBM Maximo Asset Management 7.6.0 and 7.6.1 does not invalidate session after logout which could allow a local user to impersonate another user on the system. IBM X-Force ID: 167451.
Affected products
- IBM Maximo Asset Management: from 7.6.0.0, before 7.6.0.10 (fixed in 7.6.0.10); from 7.6.1.0, before 7.6.1.1 (fixed in 7.6.1.1)
Published 2020-07-13. Last modified 2026-06-17.