Ibm Smartcloud Control Desk vulnerabilities
56 known vulnerabilities affecting ibm/smartcloud_control_desk.
Total CVEs
56
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM38LOW16
Vulnerabilities
Page 1 of 3
CVE-2013-3323P3CRITICALCVSS 9.8v7.52020-02-18
CVE-2013-3323 [CRITICAL] CWE-269 CVE-2013-3323: A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 7.5, 7.1, and 6.2, when W
A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 7.5, 7.1, and 6.2, when WebSeal with Basic Authentication is used, due to a failure to invalidate the authentication session, which could let a malicious user obtain unauthorized access.
nvd
CVE-2018-1524P3HIGHCVSS 8.8v7.6.0.0v7.6.0.12018-08-03
CVE-2018-1524 [HIGH] CVE-2018-1524: IBM Maximo Asset Management 7.6 through 7.6.3 installs with a default administrator account that a r
IBM Maximo Asset Management 7.6 through 7.6.3 installs with a default administrator account that a remote intruder could use to gain administrator access to the system. This vulnerability is due to an incomplete fix for CVE-2015-4966. IBM X-Force ID: 142116.
nvd
CVE-2013-4016P3MEDIUMCVSS 6.5v7.0v7.5+5 more2014-05-26
CVE-2013-4016 [MEDIUM] CWE-89 CVE-2013-4016: SQL injection vulnerability in IBM Maximo Asset Management 7.x before 7.1.1.7 LAFIX.20140319-0837, 7
SQL injection vulnerability in IBM Maximo Asset Management 7.x before 7.1.1.7 LAFIX.20140319-0837, 7.1.1.11 before IFIX.20140323-0749, 7.1.1.12 before IFIX.20140321-1336, 7.5.x before 7.5.0.3 IFIX027, 7.5.0.4 before IFIX011, and 7.5.0.5 before IFIX006; SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2; and Tivoli IT Asset Management
nvd
CVE-2015-4967P3MEDIUMCVSS 6.5v7.52015-10-06
CVE-2015-4967 [MEDIUM] CWE-89 CVE-2015-4967: SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.
SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX004, and 7.6.0 before 7.6.0.1 IFIX002; Maximo Asset Management 7.5.x before 7.5.0.8 IFIX004 and 7.6.0 before 7.6.0.1 IFIX002 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT
nvd
CVE-2012-0728P3MEDIUMCVSS 6.5v7.02012-09-10
CVE-2012-0728 [MEDIUM] CWE-89 CVE-2012-0728: SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.5, as used in SmartCloud Co
SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
nvd
CVE-2012-0727P3MEDIUMCVSS 6.5v7.02012-09-10
CVE-2012-0727 [MEDIUM] CWE-89 CVE-2012-0727: SQL injection vulnerability in IBM Maximo Asset Management 7.5, as used in SmartCloud Control Desk,
SQL injection vulnerability in IBM Maximo Asset Management 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
nvd
CVE-2012-0747P3MEDIUMCVSS 6.5v7.02012-09-10
CVE-2012-0747 [MEDIUM] CWE-89 CVE-2012-0747: SQL injection vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Co
SQL injection vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
nvd
CVE-2015-7448P3MEDIUMCVSS 5.4v7.5v7.5.0.1+10 more2016-03-12
CVE-2015-7448 [MEDIUM] CWE-89 CVE-2015-7448: SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.
SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.9 IFIX003, and 7.6.0 before 7.6.0.3 IFIX001; Maximo Asset Management 7.5.0 before 7.5.0.9 IFIX003, 7.5.1, and 7.6.0 before 7.6.0.3 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Managemen
nvd
CVE-2012-2183P4MEDIUMCVSS 6.8v7.02012-09-10
CVE-2012-2183 [MEDIUM] CVE-2012-2183: Session fixation vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud
Session fixation vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to hijack web sessions via unspecified vectors.
nvd
CVE-2015-4966P4MEDIUMCVSS 6.5v7.5v7.62015-11-08
CVE-2015-4966 [MEDIUM] CWE-255 CVE-2015-4966: IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.9 FP009, and 7.6.0 before 7.6.0
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.9 FP009, and 7.6.0 before 7.6.0.2 IFIX001; Maximo Asset Management 7.5.0 before 7.5.0.9 FP009, 7.5.1, and 7.6.0 before 7.6.0.2 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other product
nvd
CVE-2012-2184P4MEDIUMCVSS 6.8v7.02012-09-10
CVE-2012-2184 [MEDIUM] CVE-2012-2184: Session fixation vulnerability in IBM Maximo Asset Management 7.1 through 7.5, as used in SmartCloud
Session fixation vulnerability in IBM Maximo Asset Management 7.1 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to hijack web sessions via unspecified vectors.
nvd
CVE-2012-6355P4MEDIUMCVSS 6.5v7.5.0.02013-02-20
CVE-2012-6355 [MEDIUM] CWE-264 CVE-2012-6355: IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tiv
IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivoli Service Request Manager 7.1 and 7.2, Maximo Service Desk 6.2, Change and Configuration Management Database (CCMDB) 7.1 and 7.2, and SmartCloud Control Desk 7.5 allow remote authenticated users to gain
nvd
CVE-2013-5465P4MEDIUMCVSS 6.5v7.0v7.5+5 more2014-05-26
CVE-2013-5465 [MEDIUM] CWE-264 CVE-2013-5465: IBM Maximo Asset Management 7.x before 7.1.1.7 LAFIX.20140319-0837, 7.1.1.11 before IFIX.20140323-07
IBM Maximo Asset Management 7.x before 7.1.1.7 LAFIX.20140319-0837, 7.1.1.11 before IFIX.20140323-0749, 7.1.1.12 before IFIX.20140321-1336, 7.5.x before 7.5.0.3 IFIX027, and 7.5.0.4 before IFIX011; SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2; and Tivoli IT Asset Management for IT, Tivoli Service Request Manager, Maximo Servic
nvd
CVE-2012-0714P4MEDIUMCVSS 6.8v7.02012-09-10
CVE-2012-0714 [MEDIUM] CWE-352 CVE-2012-0714: Cross-site request forgery (CSRF) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as u
Cross-site request forgery (CSRF) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to hijack the authentication of unspecified victims vi
nvd
CVE-2012-3321P4MEDIUMCVSS 6.5v7.52013-02-20
CVE-2012-3321 [MEDIUM] CWE-264 CVE-2012-3321: IBM SmartCloud Control Desk 7.5 allows remote authenticated users to bypass intended access restrict
IBM SmartCloud Control Desk 7.5 allows remote authenticated users to bypass intended access restrictions via vectors involving an expired password.
nvd
CVE-2012-6357P4MEDIUMCVSS 6.5v7.5.0.02013-02-20
CVE-2012-6357 [MEDIUM] CWE-264 CVE-2012-6357: IBM Maximo Asset Management 7.5, Maximo Asset Management Essentials 7.5, and SmartCloud Control Desk
IBM Maximo Asset Management 7.5, Maximo Asset Management Essentials 7.5, and SmartCloud Control Desk 7.5 allow remote authenticated users to gain privileges and bypass intended restrictions on asset-lookup operations via unspecified vectors.
nvd
CVE-2012-6356P4MEDIUMCVSS 6.5v7.5.0.02013-02-20
CVE-2012-6356 [MEDIUM] CWE-264 CVE-2012-6356: IBM Maximo Asset Management 7.5, Maximo Asset Management Essentials 7.5, and SmartCloud Control Desk
IBM Maximo Asset Management 7.5, Maximo Asset Management Essentials 7.5, and SmartCloud Control Desk 7.5 allow remote authenticated users to gain privileges via vectors related to an import operation.
nvd
CVE-2015-5017P4MEDIUMCVSS 5.4v7.5v7.62016-01-03
CVE-2015-5017 [MEDIUM] CWE-284 CVE-2015-5017: IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX005, and 7.6.0 before 7.6
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX005, and 7.6.0 before 7.6.0.2 IFIX002; Maximo Asset Management 7.5.0 before 7.5.0.8 IFIX005, 7.5.1, and 7.6.0 before 7.6.0.2 IFIX002 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other pro
nvd
CVE-2014-3084P4MEDIUMCVSS 4.9v7.0v7.5+7 more2014-08-29
CVE-2014-3084 [MEDIUM] CWE-264 CVE-2014-3084: IBM Maximo Asset Management 6.1 through 6.5, 7.1 through 7.1.1.13, and 7.5 through 7.5.0.6; Maximo A
IBM Maximo Asset Management 6.1 through 6.5, 7.1 through 7.1.1.13, and 7.5 through 7.5.0.6; Maximo Asset Management 7.5.0 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk; and Maximo Asset Management 6.2.8, 7.1, and 7.2 for Tivoli IT Asset Management for IT and certain other products allow remote authenticated users to bypass inte
nvd
CVE-2013-5464P4MEDIUMCVSS 6.0v7.0v7.5+5 more2014-05-26
CVE-2013-5464 [MEDIUM] CWE-264 CVE-2013-5464: IBM Maximo Asset Management 7.5.x before 7.5.0.3 IFIX027, 7.5.0.4 before IFIX011, and 7.5.0.5 before
IBM Maximo Asset Management 7.5.x before 7.5.0.3 IFIX027, 7.5.0.4 before IFIX011, and 7.5.0.5 before IFIX006 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allow remote authenticated users to bypass intended access restrictions, and modify physical counts associated with restricted storerooms, via unspecified vectors.
nvd
1 / 3Next →