CVE-2015-7396

CWE-2643 documents3 sources
Severity
5.4MEDIUM
EPSS
0.1%
top 67.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 2
Latest updateMay 17

Description

The Scheduler in IBM Maximo Asset Management 7.5 before 7.5.0.8 IF6 and 7.6 before 7.6.0.1 FP1 and Maximo Asset Management 7.5 before 7.5.0.8 IF6, 7.5.1, and 7.6 before 7.6.0.1 FP1 for SmartCloud Control Desk allows remote authenticated users to bypass intended access restrictions, and obtain sensitive information or modify data, via unspecified vectors.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.5

Affected Packages4 packages

🔴Vulnerability Details

2
GHSA
GHSA-h5g7-49ww-h69p: The Scheduler in IBM Maximo Asset Management 72022-05-17
CVEList
CVE-2015-7396: The Scheduler in IBM Maximo Asset Management 72016-01-02
CVE-2015-7396 (MEDIUM CVSS 5.4) | The Scheduler in IBM Maximo Asset M | cvebase.io