Vulnerability CVE-2013-3323


Published: 2020-02-18

Description:
A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 7.5, 7.1, and 6.2, when WebSeal with Basic Authentication is used, due to a failure to invalidate the authentication session, which could let a malicious user obtain unauthorized access.

Type:

CWE-269

(Improper Privilege Management)

CVSS2 => (AV:N/AC:M/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.8/10
6.4/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
IBM -> Change and configuration management database 
IBM -> Maximo asset management 
IBM -> Maximo asset management essentials 
IBM -> Maximo for government 
IBM -> Maximo for life sciences 
IBM -> Maximo for nuclear power 
IBM -> Maximo for oil and gas 
IBM -> Maximo for transportation 
IBM -> Maximo for utilities 
IBM -> Maximo service desk 
IBM -> Smartcloud control desk 
IBM -> Tivoli asset management for it 
IBM -> Tivoli service request manager 

 References:
http://www.securityfocus.com/bid/62685
https://exchange.xforce.ibmcloud.com/vulnerabilities/77920?_ga=2.229912220.1881683942.1582039056-713214152.1572980240
https://www.ibm.com/support/pages/node/235239

Copyright 2024, cxsecurity.com

 

Back to Top