CVE-2015-7396

MEDIUM

IBM Maximo Asset Management 7.5-7.6 - Authenticated Access Control Bypass

Title source: llm
STIX 2.1

Description

The Scheduler in IBM Maximo Asset Management 7.5 before 7.5.0.8 IF6 and 7.6 before 7.6.0.1 FP1 and Maximo Asset Management 7.5 before 7.5.0.8 IF6, 7.5.1, and 7.6 before 7.6.0.1 FP1 for SmartCloud Control Desk allows remote authenticated users to bypass intended access restrictions, and obtain sensitive information or modify data, via unspecified vectors.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21970799

Scores

CVSS v3 5.4
EPSS 0.0079
EPSS Percentile 52.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Details

CWE
CWE-264
Status published
Products (12)
ibm/maximo_asset_management 7.5
ibm/maximo_asset_management 7.6
ibm/maximo_asset_management_essentials 7.5
ibm/maximo_for_government 7.5
ibm/maximo_for_life_sciences 7.5
ibm/maximo_for_life_sciences 7.6
ibm/maximo_for_nuclear_power 7.5
ibm/maximo_for_oil_and_gas 7.5
ibm/maximo_for_transportation 7.5
ibm/maximo_for_utilities 7.5
... and 2 more
Published Jan 02, 2016
Tracked Since Feb 18, 2026