Authentication Bypass in IBM Maximo Asset Management by Remote Users
CVE-2015-5017
5.4MEDIUM
Key Information:
- Vendor
IBM
- Status
- Vendor
- CVE Published:
- 3 January 2016
What is CVE-2015-5017?
IBM Maximo Asset Management is affected by a vulnerability that allows remote authenticated users to bypass intended access restrictions. This occurs when an attacker is able to establish a login session by using an expired password, potentially leading to unauthorized access to sensitive features and data. Users of affected versions must apply patched updates to mitigate this risk.