Maximo Service Desk

Vendor:

First CVE: Mar 13, 2012 · Active for 14 years

28
Total CVEs
More Total CVEs than 97% of tracked products
7.0
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
5.2
Avg CVSS
Higher Avg CVSS than 11% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Maximo Service Desk over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 13, 2012
14 years ago
Most Recent CVE
Feb 18, 2020
2,352 days ago

CVE Severity & Scoring

Maximo Service Desk28 CVEs
All CVEs353,173 CVEs
LowMediumCritical
Attack Vector
Local0 (0.0%)
Network1 (3.6%)
Unknown27 (96.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (3.6%)
High0 (0.0%)
Unknown27 (96.4%)
User Interaction
None1 (3.6%)
Unknown27 (96.4%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (3.6%)
Unknown27 (96.4%)

Top CVEs

Signals from CVEs in this product scope (28 CVEs).

28 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 7.5, 7.1, and 6.2, when WebSeal with Basic Authentication is used, due to a failure to invalidate the aut
Feb 18, 20209.831NONO
SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maxi
Sep 10, 20126.523NONO
Session fixation vulnerability in IBM Maximo Asset Management 7.1 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, M
Sep 10, 20126.822NONO
Session fixation vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, M
Sep 10, 20126.822NONO
Cross-site request forgery (CSRF) vulnerability in the Labor Reporting page in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Manag
Mar 13, 20126.822NONO
IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivoli Service Request Manager 7.1
Feb 20, 20136.521NONO
SQL injection vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maxi
Sep 10, 20126.521NONO
SQL injection vulnerability in the KPI component in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and
Mar 13, 20126.521NONO
SQL injection vulnerability in IBM Maximo Asset Management 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service D
Sep 10, 20126.520NONO
Cross-site request forgery (CSRF) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service R
Sep 10, 20126.820NONO

Exploit Exposure

Signals from CVEs in this product scope (28 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (28 CVEs).

Media Mentions

Signals from CVEs in this product scope (28 CVEs).

Top CNAs Publishing CVEs For Maximo Service Desk

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.1.1.813.50.9%00
7.1.1.754.71.0%00
7.1.1.1245.01.0%00
7.1.1.1135.51.1%00
6.2205.51.4%00