HTTP: IBM Maximo Asset Management Information Disclosure

This signature detects attempts to exploit a known vulnerability against IBM Maximo. A successful attack can lead to sensitive information disclosure.

Extended Description

IBM Maximo Asset Management 7.6.0.1 and 7.6.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 181484.

Affected Products

Ibm maximo_asset_management

References

CVE: CVE-2020-4463

Short Name
HTTP:CTS:IBM-MAXIMO-INFO-DISCLS
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Asset CVE-2020-4463 Disclosure IBM Information Management Maximo
Release Date
08/03/2023
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3621
False Positive
Unknown
Vendors

Ibm

Found a potential security threat?