Ibm Smartcloud Control Desk vulnerabilities
56 known vulnerabilities affecting ibm/smartcloud_control_desk.
Total CVEs
56
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM38LOW16
Vulnerabilities
Page 2 of 3
CVE-2015-7396P4MEDIUMCVSS 5.4v7.5v7.62016-01-02
CVE-2015-7396 [MEDIUM] CWE-264 CVE-2015-7396: The Scheduler in IBM Maximo Asset Management 7.5 before 7.5.0.8 IF6 and 7.6 before 7.6.0.1 FP1 and M
The Scheduler in IBM Maximo Asset Management 7.5 before 7.5.0.8 IF6 and 7.6 before 7.6.0.1 FP1 and Maximo Asset Management 7.5 before 7.5.0.8 IF6, 7.5.1, and 7.6 before 7.6.0.1 FP1 for SmartCloud Control Desk allows remote authenticated users to bypass intended access restrictions, and obtain sensitive information or modify data, via unspecified vecto
nvd
CVE-2014-0849P4MEDIUMCVSS 6.0v7.0v7.5+6 more2014-05-26
CVE-2014-0849 [MEDIUM] CWE-264 CVE-2014-0849: IBM Maximo Asset Management 7.x before 7.5.0.3 IFIX027 and SmartCloud Control Desk 7.x before 7.5.0.
IBM Maximo Asset Management 7.x before 7.5.0.3 IFIX027 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allow remote authenticated users to gain privileges by leveraging membership in two security groups.
nvd
CVE-2014-3024P4MEDIUMCVSS 6.0v7.5.0.0v7.5.0.1+5 more2014-08-29
CVE-2014-3024 [MEDIUM] CWE-352 CVE-2014-3024: Cross-site request forgery (CSRF) vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.12
Cross-site request forgery (CSRF) vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.12 and 7.5 through 7.5.0.6 and Maximo Asset Management 7.5.0 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk allows remote authenticated users to hijack the authentication of arbitrary users.
nvd
CVE-2015-1934P4MEDIUMCVSS 5.0v7.52015-10-04
CVE-2015-1934 [MEDIUM] CWE-310 CVE-2015-1934: IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX002, and 7.6.0 before 7.6
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX002, and 7.6.0 before 7.6.0.1 IFIX001; Maximo Asset Management 7.5.x before 7.5.0.8 IFIX002 and 7.6.0 before 7.6.0.1 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products do
nvd
CVE-2012-3333P4MEDIUMCVSS 4.3v7.0v7.5+5 more2014-05-26
CVE-2012-3333 [MEDIUM] CVE-2012-3333: CRLF injection vulnerability in IBM Maximo Asset Management 7.x before 7.5.0.6 and SmartCloud Contro
CRLF injection vulnerability in IBM Maximo Asset Management 7.x before 7.5.0.6 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted parameter in a URL.
nvd
CVE-2019-4486P4MEDIUMCVSS 5.4v7.6.0v7.6.0.12019-10-24
CVE-2019-4486 [MEDIUM] CWE-79 CVE-2019-4486: IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows use
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 164070.
nvd
CVE-2015-7451P4MEDIUMCVSS 5.4v7.5v7.62016-01-02
CVE-2015-7451 [MEDIUM] CWE-79 CVE-2015-7451: Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5 before 7.5.0.9 IF2 and 7
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5 before 7.5.0.9 IF2 and 7.6 before 7.6.0.3 FP3 and Maximo Asset Management 7.5 before 7.5.0.9 IF2, 7.5.1, and 7.6 before 7.6.0.3 FP3 for SmartCloud Control Desk allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2014-6194P4MEDIUMCVSS 4.0v7.5.0.1v7.5.0.2+4 more2015-02-17
CVE-2014-6194 [MEDIUM] CWE-22 CVE-2014-6194: Directory traversal vulnerability in an unspecified web form in IBM Maximo Asset Management 7.1 thro
Directory traversal vulnerability in an unspecified web form in IBM Maximo Asset Management 7.1 through 7.1.1.13 and 7.5.0 before 7.5.0.6 IFIX007, Maximo Asset Management 7.5.0 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk, and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain
nvd
CVE-2015-5051P4MEDIUMCVSS 4.3v7.5v7.62016-01-03
CVE-2015-5051 [MEDIUM] CWE-264 CVE-2015-5051: IBM Maximo Asset Management 7.5 before 7.5.0.8 IF6 and 7.6 before 7.6.0.2 IF1 and Maximo Asset Manag
IBM Maximo Asset Management 7.5 before 7.5.0.8 IF6 and 7.6 before 7.6.0.2 IF1 and Maximo Asset Management 7.5 before 7.5.0.8 IF6, 7.5.1, and 7.6 before 7.6.0.2 IF1 for SmartCloud Control Desk allow remote authenticated users to bypass intended access restrictions on query results via unspecified vectors.
nvd
CVE-2014-4765P4MEDIUMCVSS 5.0v7.5.0.1v7.5.0.2+4 more2014-10-02
CVE-2014-4765 [MEDIUM] CWE-200 CVE-2014-4765: IBM Maximo Asset Management 7.1 through 7.1.1.13 and 7.5 through 7.5.0.6, Maximo Asset Management 7.
IBM Maximo Asset Management 7.1 through 7.1.1.13 and 7.5 through 7.5.0.6, Maximo Asset Management 7.5.0 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk, and Maximo Asset Management 7.1 and 7.2 for Tivoli IT Asset Management for IT and certain other products allow remote attackers to obtain sensitive directory information by readi
nvd
CVE-2018-1528P4MEDIUMCVSS 4.3v7.6.0.0v7.6.0.12018-08-06
CVE-2018-1528 [MEDIUM] CWE-200 CVE-2018-1528: IBM Maximo Asset Management 7.6 through 7.6.3 could allow an authenticated user to obtain sensitive
IBM Maximo Asset Management 7.6 through 7.6.3 could allow an authenticated user to obtain sensitive information from the WhoAmI API. IBM X-Force ID: 142290.
nvd
CVE-2012-3327P4MEDIUMCVSS 4.3v7.5.0.02013-02-20
CVE-2012-3327 [MEDIUM] CWE-79 CVE-2012-3327: Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, Maximo Asse
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivoli Service Request Manager 7.1 and 7.2, Maximo Service Desk 6.2, Change and Configuration Management Database (CCMDB) 7.1 and 7.2, and SmartCloud Control Desk 7.
nvd
CVE-2015-7452P4MEDIUMCVSS 4.3v7.5v7.62016-01-02
CVE-2015-7452 [MEDIUM] CWE-200 CVE-2015-7452: IBM Maximo Asset Management 7.5 before 7.5.0.9 FP9 and 7.6 before 7.6.0.3 FP3 and Maximo Asset Manag
IBM Maximo Asset Management 7.5 before 7.5.0.9 FP9 and 7.6 before 7.6.0.3 FP3 and Maximo Asset Management 7.5 before 7.5.0.9 FP9, 7.5.1, and 7.6 before 7.6.0.3 FP3 for SmartCloud Control Desk allow remote authenticated users to obtain sensitive information via the REST API.
nvd
CVE-2015-7395P4MEDIUMCVSS 4.0v7.5v7.62015-11-08
CVE-2015-7395 [MEDIUM] CWE-284 CVE-2015-7395: IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX005, and 7.6.0 before 7.6
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX005, and 7.6.0 before 7.6.0.2 FP002; Maximo Asset Management 7.5.0 before 7.5.0.8 IFIX005, 7.5.1, and 7.6.0 before 7.6.0.2 FP002 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other product
nvd
CVE-2012-3326P4MEDIUMCVSS 4.3v7.02012-09-10
CVE-2012-3326 [MEDIUM] CWE-79 CVE-2012-3326: Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5, as used in SmartCloud C
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2012-3313P4MEDIUMCVSS 4.3v7.02012-09-10
CVE-2012-3313 [MEDIUM] CWE-79 CVE-2012-3313: Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2014-0893P4MEDIUMCVSS 4.3v7.0v7.5+7 more2014-05-26
CVE-2014-0893 [MEDIUM] CWE-79 CVE-2014-0893: Cross-site scripting (XSS) vulnerability in customreport.jsp in IBM Maximo Asset Management 7.5.x be
Cross-site scripting (XSS) vulnerability in customreport.jsp in IBM Maximo Asset Management 7.5.x before 7.5.0.5 IFIX006 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified parameters.
nvd
CVE-2014-3026P4LOWCVSS 3.5v7.5.0.0v7.5.0.1+6 more2014-07-29
CVE-2014-3026 [LOW] CVE-2014-3026: CRLF injection vulnerability in IBM Maximo Asset Management 7.5 through 7.5.0.6, and 7.5 through 7.5
CRLF injection vulnerability in IBM Maximo Asset Management 7.5 through 7.5.0.6, and 7.5 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk, allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
nvd
CVE-2015-4965P4MEDIUMCVSS 4.0v7.52015-10-06
CVE-2015-4965 [MEDIUM] CWE-200 CVE-2015-4965: maximouiweb/webmodule/webclient/utility/merlin.jsp in IBM Maximo Asset Management 7.1 through 7.1.1.
maximouiweb/webmodule/webclient/utility/merlin.jsp in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX004, and 7.6.0 before 7.6.0.1 IFIX002; Maximo Asset Management 7.5.x before 7.5.0.8 IFIX004 and 7.6.0 before 7.6.0.1 IFIX002 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT
nvd
CVE-2012-2185P4MEDIUMCVSS 4.0v7.02012-09-10
CVE-2012-2185 [MEDIUM] CWE-200 CVE-2012-2185: IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Manage
IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote authenticated users to obtain sensitive information via unspecified vectors.
nvd