Access Bypass Vulnerability in IBM Maximo Asset Management
CVE-2015-5051
4.3MEDIUM
Key Information:
- Vendor
- IBM
- Vendor
- CVE Published:
- 3 January 2016
Summary
IBM Maximo Asset Management versions 7.5 before 7.5.0.8 IF6 and 7.6 before 7.6.0.2 IF1 are susceptible to an access control bypass vulnerability. This flaw allows remote authenticated users to circumvent intended access restrictions on query results through unspecified vectors, potentially exposing sensitive data or functions that should be restricted. Organizations using affected versions of IBM Maximo should consider applying the latest updates to mitigate this vulnerability.
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved