Vulnerability CVE-2012-6355


Published: 2013-02-20

Description:
IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivoli Service Request Manager 7.1 and 7.2, Maximo Service Desk 6.2, Change and Configuration Management Database (CCMDB) 7.1 and 7.2, and SmartCloud Control Desk 7.5 allow remote authenticated users to gain privileges via vectors related to a work order.

Type:

CWE-264

(Permissions, Privileges, and Access Controls)

CVSS2 => (AV:N/AC:L/Au:S/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.5/10
6.4/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
IBM -> Change and configuration management database 
IBM -> Maximo asset management 
IBM -> Maximo asset management essentials 
IBM -> Maximo service desk 
IBM -> Smartcloud control desk 
IBM -> Tivoli asset management for it 
IBM -> Tivoli service request manager 

 References:
http://xforce.iss.net/xforce/xfdb/80747
http://www-01.ibm.com/support/docview.wss?uid=swg21625624
http://www-01.ibm.com/support/docview.wss?uid=swg1IV30384

Copyright 2024, cxsecurity.com

 

Back to Top