CVE-2015-7396
MEDIUMIBM Maximo Asset Management - Access Control
Title source: ruleDescription
The Scheduler in IBM Maximo Asset Management 7.5 before 7.5.0.8 IF6 and 7.6 before 7.6.0.1 FP1 and Maximo Asset Management 7.5 before 7.5.0.8 IF6, 7.5.1, and 7.6 before 7.6.0.1 FP1 for SmartCloud Control Desk allows remote authenticated users to bypass intended access restrictions, and obtain sensitive information or modify data, via unspecified vectors.
Scores
CVSS v3
5.4
EPSS
0.0013
EPSS Percentile
32.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Classification
CWE
CWE-264
Status
draft
Affected Products (12)
ibm/maximo_asset_management
ibm/maximo_asset_management
ibm/maximo_asset_management_essentials
ibm/maximo_for_government
ibm/maximo_for_life_sciences
ibm/maximo_for_life_sciences
ibm/maximo_for_nuclear_power
ibm/maximo_for_oil_and_gas
ibm/maximo_for_transportation
ibm/maximo_for_utilities
ibm/smartcloud_control_desk
ibm/smartcloud_control_desk
Timeline
Published
Jan 02, 2016
Tracked Since
Feb 18, 2026