CVE-2015-4967
IBM Maximo Asset Management 7.1-7.1.1.13, 7.5.0 < 7.5.0.8 IFIX004, 7.6.0 < 7.6.0.1 IFIX002 - Authenticated SQL Injection
Title source: llmDescription
SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX004, and 7.6.0 before 7.6.0.1 IFIX002; Maximo Asset Management 7.5.x before 7.5.0.8 IFIX004 and 7.6.0 before 7.6.0.1 IFIX002 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
References (1)
Core 1
Core References
Patch, Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21966181
Scores
EPSS
0.0099
EPSS Percentile
58.9%
Details
CWE
CWE-89
Status
published
Products (50)
ibm/change_and_configuration_management_database
7.1
ibm/change_and_configuration_management_database
7.2
ibm/maximo_asset_management
7.1
ibm/maximo_asset_management
7.1.1
ibm/maximo_asset_management
7.1.1.1
ibm/maximo_asset_management
7.1.1.2
ibm/maximo_asset_management
7.1.1.5
ibm/maximo_asset_management
7.1.1.6
ibm/maximo_asset_management
7.1.1.7
ibm/maximo_asset_management
7.1.1.8
... and 40 more
Published
Oct 06, 2015
Tracked Since
Feb 18, 2026