CVE-2015-5016
4.3
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD
Description
IBM Maximo Asset Management 7.1, 7.5, and 7.6; Maximo Asset Management Essentials 7.1 and 7.5; Control Desk 7.5 and 7.6; Tivoli Asset Management for IT 7.1 and 7.2; and certain other IBM products allow remote authenticated users to bypass intended access restrictions and read arbitrary ticket worklog entries via unspecified vectors. IBM X-Force ID: 106460.
Affected (29)
Products: Ibm: Maximo Asset Management, Maximo Asset Management Essentials, Maximo For Energy Optimization, Maximo For Aviation, Maximo For Government, Maximo For Nuclear Power, Maximo For Transportation, Maximo For Life Sciences, Maximo For Oil And Gas, Maximo For Utilities, Control Desk, Tivoli Asset Management For It, Tivoli Service Request Manager, Change And Configuration Management Database
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.1 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.1 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.1 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.6 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.1 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.1 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.1 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.1 |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.1 |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.1 |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.5 |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.1 |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.1 |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.1 |
References (4)
Source: psirt@us.ibm.com
PatchVendor Advisory
Source: psirt@us.ibm.com
VDB EntryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
VDB EntryVendor Advisory
Timeline
No history available yet.