SQL Injection Vulnerability in IBM Maximo Asset Management
CVE-2015-7448
5.4MEDIUM
Key Information:
- Vendor
- IBM
- Status
- Vendor
- CVE Published:
- 12 March 2016
Summary
An SQL injection vulnerability exists in IBM Maximo Asset Management products, affecting versions 7.1 through 7.1.1.13 and various other iterations. This flaw permits remote authenticated users to execute arbitrary SQL commands, potentially compromising sensitive data. Organizations using affected versions should consider immediate security measures to mitigate risks associated with unauthorized access and data breaches.
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved