9.8

CVE-2013-3323

A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 7.5, 7.1, and 6.2, when WebSeal with Basic Authentication is used, due to a failure to invalidate the authentication session, which could let a malicious user obtain unauthorized access.

Data is provided by the National Vulnerability Database (NVD)
IbmMaximo Asset Management Version6.2
IbmMaximo Asset Management Version7.1
IbmMaximo Asset Management Version7.5
IbmMaximo For Government Version6.2
IbmMaximo For Government Version7.1
IbmMaximo For Government Version7.5
IbmMaximo For Life Sciences Version6.2
IbmMaximo For Life Sciences Version6.4
IbmMaximo For Life Sciences Version6.5
IbmMaximo For Life Sciences Version7.1
IbmMaximo For Life Sciences Version7.5
IbmMaximo For Nuclear Power Version6.2
IbmMaximo For Nuclear Power Version6.3
IbmMaximo For Nuclear Power Version7.1
IbmMaximo For Nuclear Power Version7.5
IbmMaximo For Oil And Gas Version6.2
IbmMaximo For Oil And Gas Version6.3
IbmMaximo For Oil And Gas Version6.4
IbmMaximo For Oil And Gas Version7.1
IbmMaximo For Oil And Gas Version7.5
IbmMaximo For Utilities Version6.2
IbmMaximo For Utilities Version6.3
IbmMaximo For Utilities Version7.1
IbmMaximo For Utilities Version7.5
IbmMaximo Service Desk Version6.2
IbmSmartcloud Control Desk Version7.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.53% 0.647
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.