CVE-2011-4817Sensitive Information Exposure in IBM Maximo Asset Management

Severity
4.0MEDIUMNVD
EPSS
0.3%
top 44.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 13
Latest updateMay 14

Description

The About option on the Help menu in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service Desk 6.2; and IBM Tivoli Change and Configuration Management Database (CCMDB) 6.2, 7.1, and 7.2 shows the username, which might allow remote authenticated users to have an unspecified impact via a targeted attack against the corresponding user account.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 8.0 | Impact: 2.9

Affected Packages6 packages

🔴Vulnerability Details

2
GHSA
GHSA-3j4r-3gwf-p2pm: The About option on the Help menu in IBM Maximo Asset Management and Asset Management Essentials 62022-05-14
CVEList
CVE-2011-4817: The About option on the Help menu in IBM Maximo Asset Management and Asset Management Essentials 62012-03-13
CVE-2011-4817 — Sensitive Information Exposure in IBM | cvebase