5.5
CVE-2015-5017
- EPSS 0.11%
- Published 03.01.2016 05:59:03
- Last modified 12.04.2025 10:46:40
- Source psirt@us.ibm.com
- Teams watchlist Login
- Open Login
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX005, and 7.6.0 before 7.6.0.2 IFIX002; Maximo Asset Management 7.5.0 before 7.5.0.8 IFIX005, 7.5.1, and 7.6.0 before 7.6.0.2 IFIX002 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products allow remote authenticated users to bypass intended access restrictions and establish a login session by entering an expired password.
Data is provided by the National Vulnerability Database (NVD)
Ibm ≫ Change And Configuration Management Database Version7.1
Ibm ≫ Change And Configuration Management Database Version7.2
Ibm ≫ Maximo Asset Management Version7.1
Ibm ≫ Maximo Asset Management Version7.5
Ibm ≫ Maximo Asset Management Version7.6
Ibm ≫ Maximo Asset Management Essentials Version7.1
Ibm ≫ Maximo Asset Management Essentials Version7.5
Ibm ≫ Maximo For Energy Optimization Version7.1
Ibm ≫ Maximo For Government Version7.1
Ibm ≫ Maximo For Government Version7.5
Ibm ≫ Maximo For Life Sciences Version7.1
Ibm ≫ Maximo For Life Sciences Version7.5
Ibm ≫ Maximo For Life Sciences Version7.6
Ibm ≫ Maximo For Nuclear Power Version7.1
Ibm ≫ Maximo For Nuclear Power Version7.5
Ibm ≫ Maximo For Oil And Gas Version7.1
Ibm ≫ Maximo For Oil And Gas Version7.5
Ibm ≫ Maximo For Transportation Version7.1
Ibm ≫ Maximo For Transportation Version7.5
Ibm ≫ Maximo For Utilities Version7.1
Ibm ≫ Maximo For Utilities Version7.5
Ibm ≫ Smartcloud Control Desk Version7.5
Ibm ≫ Smartcloud Control Desk Version7.6
Ibm ≫ Tivoli Asset Management For It Version7.1
Ibm ≫ Tivoli Asset Management For It Version7.2
Ibm ≫ Tivoli Service Request Manager Version7.1
Ibm ≫ Tivoli Service Request Manager Version7.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.11% | 0.255 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 5.4 | 2.8 | 2.5 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
|
nvd@nist.gov | 5.5 | 8 | 4.9 |
AV:N/AC:L/Au:S/C:P/I:P/A:N
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.