4.3
CVE-2015-7452
- EPSS 0.89%
- Veröffentlicht 02.01.2016 21:59:16
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
IBM Maximo Asset Management 7.5 before 7.5.0.9 FP9 and 7.6 before 7.6.0.3 FP3 and Maximo Asset Management 7.5 before 7.5.0.9 FP9, 7.5.1, and 7.6 before 7.6.0.3 FP3 for SmartCloud Control Desk allow remote authenticated users to obtain sensitive information via the REST API.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Maximo Asset Management Version 7.5
Ibm ≫ Maximo Asset Management Version 7.6
Ibm ≫ Maximo Asset Management Essentials Version 7.5
Ibm ≫ Maximo For Government Version 7.5
Ibm ≫ Maximo For Life Sciences Version 7.5
Ibm ≫ Maximo For Life Sciences Version 7.6
Ibm ≫ Maximo For Nuclear Power Version 7.5
Ibm ≫ Maximo For Oil And Gas Version 7.5
Ibm ≫ Maximo For Transportation Version 7.5
Ibm ≫ Maximo For Utilities Version 7.5
Ibm ≫ Smartcloud Control Desk Version 7.5
Ibm ≫ Smartcloud Control Desk Version 7.6
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.89% | 0.546 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.3 | 2.8 | 1.4 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
| NIST | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
http://www-01.ibm.com/support/docview.wss?uid=swg21972463