LiveActive security incident?Get immediate response
CVE Record

CVE-2021-20509: IBM Maximo Asset Management 7.6.0 and 7.6.1 is potentially vulnerable to CSV Injection.

IBM Maximo Asset Management 7.6.0 and 7.6.1 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 198243.

HighCVSS 7Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

IBM Maximo Asset Management 7.6.0 and 7.6.1 can mishandle CSV content. If abused, a user-mediated CSV workflow could lead to arbitrary command execution on a system. The issue is rated high, but the available evidence does not show active exploitation.

Executive priority

Prioritize remediation for affected Maximo environments that support business-critical asset operations or frequent CSV workflows. This is high impact but not currently supported by evidence of active exploitation in the provided sources.

Technical view

CVE-2021-20509 is a CSV Injection issue in IBM Maximo Asset Management 7.6.0 and 7.6.1. The CVSS 3.0 score is 7.0 with high confidentiality, integrity, and availability impact, high attack complexity, no privileges required, and user interaction required. IBM X-Force tracks it as 198243.

Likely exposure

Exposure appears limited to IBM Maximo Asset Management 7.6.0 and 7.6.1. Organizations should focus on deployments using CSV import, export, or file-handling workflows. The source bundle does not identify other IBM products or later Maximo versions as affected.

Exploitation context

The CVE is not listed as CISA KEV in the provided bundle. The CVSS vector lists exploit maturity as unproven and requires user interaction. IBM says arbitrary commands could execute because CSV file contents are not properly validated, but the sources do not provide public exploit evidence.

Researcher notes

Key tension: IBM describes a remote attacker outcome, while CVSS lists local attack vector and user interaction. Treat exploitation as user-mediated unless vendor guidance clarifies otherwise. Do not broaden affected scope beyond Maximo Asset Management 7.6.0 and 7.6.1.

Mitigation direction

  • Review IBM advisory 6480377 and X-Force 198243 for official remediation guidance.
  • Apply IBM-provided fixes or upgrades applicable to your Maximo version.
  • Restrict CSV handling to trusted users and controlled workstations until remediated.
  • Warn users not to open untrusted Maximo-related CSV files in spreadsheet tools.
  • Monitor IBM support guidance if your deployment differs from 7.6.0 or 7.6.1.

Validation and detection

  • Inventory Maximo Asset Management instances and confirm exact version numbers.
  • Identify CSV import, export, and reporting workflows tied to Maximo.
  • Check whether IBM remediation has been applied to affected instances.
  • Review user access to CSV-producing or CSV-consuming Maximo functions.
  • Confirm security monitoring covers suspicious spreadsheet-launched process activity.
Prepared
Confidence
high
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2021-20509 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
7 (3.0)
Known Exploited
No
Published

Vector: CVSS:3.0/I:H/AC:H/S:U/A:H/UI:R/AV:L/PR:N/C:H/RC:C/RL:O/E:U

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
7CVSS 3.0HighCVSS:3.0/I:H/AC:H/S:U/A:H/UI:R/AV:L/PR:N/C:H/RC:C/RL:O/E:U15.9Primary CVE score

Vulnerability scoring details

Base CVSS 3.0 score

7High
CVSS 3.0 vector shape for CVE-2021-20509Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.0/I:H/AC:H/S:U/A:H/UI:R/AV:L/PR:N/C:H/RC:C/RL:O/E:U

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
IBMMaximo Asset Management7.6.0, 7.6.1Listed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.