Access Control Bypass Vulnerability in IBM Maximo Asset Management
CVE-2016-0222
4.3MEDIUM
Key Information:
- Vendor
- IBM
- Vendor
- CVE Published:
- 14 March 2016
Summary
IBM Maximo Asset Management versions prior to 7.6.0.3 IFIX001 are susceptible to an access control bypass vulnerability. This issue allows remote authenticated users to circumvent intended security measures, enabling them to read arbitrary purchase-order work logs through unspecified methods. Organizations using affected versions should evaluate their security posture and apply the necessary updates to mitigate this vulnerability.
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved