← Back

CVE-2013-4016

nvd nist
Published: May 26, 2014Modified: May 6, 2026

JSON object

Loading...
6.5
Vector
AV:N/AC:L/Au:S/C:P/I:P/A:P
Exploitability: 8.0 / Impact: 6.4
Source: NVD

Description

SQL injection vulnerability in IBM Maximo Asset Management 7.x before 7.1.1.7 LAFIX.20140319-0837, 7.1.1.11 before IFIX.20140323-0749, 7.1.1.12 before IFIX.20140321-1336, 7.5.x before 7.5.0.3 IFIX027, 7.5.0.4 before IFIX011, and 7.5.0.5 before IFIX006; SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2; and Tivoli IT Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB) 7.x before 7.1.1.7 LAFIX.20140319-0837, 7.1.1.11 before IFIX.20140207-1801, and 7.1.1.12 before IFIX.20140218-1510 allows remote authenticated users to execute arbitrary SQL commands via a Birt report with a WHERE clause in plain text.

Affected (37)

7 products
Maximo Service Desk
Tivoli Asset Management For It
Tivoli It Asset Management For It
Tivoli Service Request Manager
Smartcloud Control Desk
Maximo Asset Management
Configuration A
15 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Ibm
Version 7.1.1.11
Version 7.1.1.12
Version 7.1.1.7
Ibm
Version 7.1.1.11
Version 7.1.1.12
Version 7.1.1.7
Ibm
Version 7.0
Version 7.1
Ibm
Version 7.1.1.11
Version 7.1.1.12
Version 7.1.1.7
Ibm
Version 7.1.1.11
Version 7.1.1.12
Version 7.1.1.7
Version 7.1.1
Running on/withPlatform Versions
Ibm
Tivoli Service Request Manager
Version 7.0
Ibm
Tivoli Service Request Manager
Version 7.1.0.0
Configuration B
7 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
Version 7.0
Version 7.5.0.0
Version 7.5.0.1
Version 7.5.0.2
Version 7.5.1.0
Version 7.5.1.1
Version 7.5
Configuration C
6 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
Version 7.5.0.0
Version 7.5.0.1
Version 7.5.0.2
Version 7.5.0.3
Version 7.5.0.4
Version 7.5.0.5
Configuration D
9 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
Version 7.1.1.11
Version 7.1.1.12
Version 7.1.1.1
Version 7.1.1.2
Version 7.1.1.5
Version 7.1.1.6
Version 7.1.1.7
Version 7.1.1
Version 7.1

References (6)

Source: psirt@us.ibm.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.