CVE-2015-7448
MEDIUMIBM Maximo Asset Management <7.6.0.3 IFIX001 - SQL Injection
Title source: llmDescription
SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.9 IFIX003, and 7.6.0 before 7.6.0.3 IFIX001; Maximo Asset Management 7.5.0 before 7.5.0.9 IFIX003, 7.5.1, and 7.6.0 before 7.6.0.3 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
Scores
CVSS v3
5.4
EPSS
0.0013
EPSS Percentile
31.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Classification
CWE
CWE-89
Status
draft
Affected Products (50)
ibm/change_and_configuration_management_database
ibm/change_and_configuration_management_database
ibm/change_and_configuration_management_database
ibm/change_and_configuration_management_database
ibm/change_and_configuration_management_database
ibm/change_and_configuration_management_database
ibm/change_and_configuration_management_database
ibm/change_and_configuration_management_database
ibm/change_and_configuration_management_database
ibm/change_and_configuration_management_database
ibm/change_and_configuration_management_database
ibm/change_and_configuration_management_database
ibm/change_and_configuration_management_database
ibm/change_and_configuration_management_database
ibm/change_and_configuration_management_database
... and 35 more
Timeline
Published
Mar 12, 2016
Tracked Since
Feb 18, 2026