CVE-2015-7452

MEDIUM

IBM Maximo Asset Management <7.5.0.9 FP9, <7.6.0.3 FP3 - Info Discl...

Title source: llm

Description

IBM Maximo Asset Management 7.5 before 7.5.0.9 FP9 and 7.6 before 7.6.0.3 FP3 and Maximo Asset Management 7.5 before 7.5.0.9 FP9, 7.5.1, and 7.6 before 7.6.0.3 FP3 for SmartCloud Control Desk allow remote authenticated users to obtain sensitive information via the REST API.

Scores

CVSS v3 4.3
EPSS 0.0015
EPSS Percentile 36.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Classification

CWE
CWE-200
Status draft

Affected Products (12)

ibm/maximo_asset_management
ibm/maximo_asset_management
ibm/maximo_asset_management_essentials
ibm/maximo_for_government
ibm/maximo_for_life_sciences
ibm/maximo_for_life_sciences
ibm/maximo_for_nuclear_power
ibm/maximo_for_oil_and_gas
ibm/maximo_for_transportation
ibm/maximo_for_utilities
ibm/smartcloud_control_desk
ibm/smartcloud_control_desk

Timeline

Published Jan 02, 2016
Tracked Since Feb 18, 2026