cbcvebase.
CVE-2015-7452
published 2016-01-02

CVE-2015-7452: IBM Maximo Asset Management 7.5 before 7.5.0.9 FP9 and 7.6 before 7.6.0.3 FP3 and Maximo Asset Management 7.5 before 7.5.0.9 FP9, 7.5.1, and 7.6 before 7.6.0.3…

PriorityP419medium4.3CVSS 3.0
AVNACLPRLUINSUCLINAN
EPSS
0.89%
55.2th percentile
IBM Maximo Asset Management 7.5 before 7.5.0.9 FP9 and 7.6 before 7.6.0.3 FP3 and Maximo Asset Management 7.5 before 7.5.0.9 FP9, 7.5.1, and 7.6 before 7.6.0.3 FP3 for SmartCloud Control Desk allow remote authenticated users to obtain sensitive information via the REST API.

Affected

12 ranges
VendorProductVersion rangeFixed in
ibmmaximo_asset_management
ibmmaximo_asset_management
ibmmaximo_asset_management_essentials
ibmmaximo_for_government
ibmmaximo_for_life_sciences
ibmmaximo_for_life_sciences
ibmmaximo_for_nuclear_power
ibmmaximo_for_oil_and_gas
ibmmaximo_for_transportation
ibmmaximo_for_utilities
ibmsmartcloud_control_desk
ibmsmartcloud_control_desk

CVSS provenance

nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.