CVE-2013-3323

Severity
9.8CRITICAL
EPSS
0.5%
top 32.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 18
Latest updateMay 5

Description

A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 7.5, 7.1, and 6.2, when WebSeal with Basic Authentication is used, due to a failure to invalidate the authentication session, which could let a malicious user obtain unauthorized access.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages8 packages

NVDibm/maximo_asset_management6.2, 7.1, 7.5+2
NVDibm/tivoli_asset_management6.2, 7.1, 7.2+2
NVDibm/maximo6 versions+5

🔴Vulnerability Details

2
GHSA
GHSA-5h7g-4px8-37g8: A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 72022-05-05
CVEList
CVE-2013-3323: A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 72020-02-18
CVE-2013-3323 (CRITICAL CVSS 9.8) | A Privilege Escalation Vulnerabilit | cvebase.io