CVE-2013-3323
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 7.5, 7.1, and 6.2, when WebSeal with Basic Authentication is used, due to a failure to invalidate the authentication session, which could let a malicious user obtain unauthorized access.
Affected (40)
Products: Ibm: Change And Configuration Management Database, Maximo Asset Management, Maximo Asset Management Essentials, Maximo For Government, Maximo For Life Sciences, Maximo For Nuclear Power, Maximo For Oil And Gas, Maximo For Transportation, Maximo For Utilities, Maximo Service Desk, Smartcloud Control Desk, Tivoli Asset Management For It, Tivoli Service Request Manager
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.1 | |
| Version 6.2 | |
| Version 6.2 | |
| Version 6.2 | |
| Version 6.2 | |
| Version 6.2 | |
| Version 6.2 | |
| Version 6.2 | |
| Version 6.2 | |
| Version 6.2 | |
| Version 7.5 | |
| Version 6.2 | |
| Version 7.1 |
References (6)
Source: cve@mitre.org
VDB EntryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
VDB EntryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.