CVE-2024-45077: IBM Maximo Asset Management
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
IBM Maximo Asset Management 7.6.1.3 MXAPIASSET API is vulnerable to unrestricted file upload which allows authenticated low privileged user to upload restricted file types with a simple method of adding a dot to the end of the file name if Maximo is installed on Windows operating system.
Affected products
- IBM Maximo Asset Management: version 7.6.1.3 only
Published 2025-01-24. Last modified 2026-06-17.