CVE-2011-4816: SQL Injection
SQL injection vulnerability in the KPI component in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service Desk 6.2; and IBM Tivoli Change and Configuration Management Database (CCMDB) 6.2, 7.1, and 7.2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4816?
CVE-2011-4816 is rated as a medium severity SQL injection vulnerability.
How do I fix CVE-2011-4816?
To fix CVE-2011-4816, apply the necessary patches provided by IBM for your affected version of the software.
Which products are affected by CVE-2011-4816?
CVE-2011-4816 affects IBM Maximo Asset Management, IBM Tivoli Asset Management for IT, and other related products.
What type of vulnerability is CVE-2011-4816?
CVE-2011-4816 is an SQL injection vulnerability that allows attackers to manipulate database queries.
Is CVE-2011-4816 included in IBM’s security updates?
Yes, CVE-2011-4816 is included in IBM's security updates for the affected products.