CVE-2015-7448

MEDIUM

IBM Maximo Asset Management <7.6.0.3 IFIX001 - SQL Injection

Title source: llm

Description

SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.9 IFIX003, and 7.6.0 before 7.6.0.3 IFIX001; Maximo Asset Management 7.5.0 before 7.5.0.9 IFIX003, 7.5.1, and 7.6.0 before 7.6.0.3 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

Scores

CVSS v3 5.4
EPSS 0.0013
EPSS Percentile 31.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Classification

CWE
CWE-89
Status draft

Affected Products (50)

ibm/change_and_configuration_management_database
ibm/change_and_configuration_management_database
ibm/change_and_configuration_management_database
ibm/change_and_configuration_management_database
ibm/change_and_configuration_management_database
ibm/change_and_configuration_management_database
ibm/change_and_configuration_management_database
ibm/change_and_configuration_management_database
ibm/change_and_configuration_management_database
ibm/change_and_configuration_management_database
ibm/change_and_configuration_management_database
ibm/change_and_configuration_management_database
ibm/change_and_configuration_management_database
ibm/change_and_configuration_management_database
ibm/change_and_configuration_management_database
... and 35 more

Timeline

Published Mar 12, 2016
Tracked Since Feb 18, 2026