CVE-2015-1934

IBM Maximo Asset Management Password Exposure via Improper Encryption

Title source: llm
STIX 2.1

Description

IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX002, and 7.6.0 before 7.6.0.1 IFIX001; Maximo Asset Management 7.5.x before 7.5.0.8 IFIX002 and 7.6.0 before 7.6.0.1 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products do not properly encrypt passwords, which makes it easier for context-dependent attackers to determine cleartext passwords by leveraging access to a password file.

References (1)

Core 1
Core References
Patch, Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21964855

Scores

EPSS 0.0099
EPSS Percentile 59.0%

Details

CWE
CWE-310
Status published
Products (50)
ibm/change_and_configuration_management_database 7.1
ibm/change_and_configuration_management_database 7.2
ibm/maximo_asset_management 7.1
ibm/maximo_asset_management 7.1.1
ibm/maximo_asset_management 7.1.1.1
ibm/maximo_asset_management 7.1.1.2
ibm/maximo_asset_management 7.1.1.5
ibm/maximo_asset_management 7.1.1.6
ibm/maximo_asset_management 7.1.1.7
ibm/maximo_asset_management 7.1.1.8
... and 40 more
Published Oct 04, 2015
Tracked Since Feb 18, 2026