CVE-2019-4671: IBM Maximo Asset Management
Medium severity, CVSS 6.3. EPSS: 0.8% chance of exploitation in the next 30 days.
IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 171437.
Affected products
- IBM Maximo Asset Management: from 7.6.0, before 7.6.0.10 (fixed in 7.6.0.10); from 7.6.1, before 7.6.1.2 (fixed in 7.6.1.2)
Published 2020-09-15. Last modified 2026-06-17.