Sensitive Information Exposure in IBM Maximo Asset Management
CVE-2015-7452
4.3MEDIUM
Key Information:
- Vendor
- IBM
- Vendor
- CVE Published:
- 2 January 2016
Summary
IBM Maximo Asset Management versions prior to 7.5.0.9 FP9 and 7.6.0.3 FP3 for SmartCloud Control Desk are susceptible to a security flaw that allows remote authenticated users to exploit the REST API. This vulnerability enables unauthorized access to sensitive information, which could lead to data leaks and compromise the integrity of the application.
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved