CVE-2012-0728: SQL Injection
SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0728?
CVE-2012-0728 has a medium severity level, indicating a moderate risk to the affected systems.
How do I fix CVE-2012-0728?
To fix CVE-2012-0728, apply the security patches provided by IBM for your affected software version.
Which IBM products are affected by CVE-2012-0728?
CVE-2012-0728 affects IBM Maximo Asset Management versions 7.1 to 7.5, IBM Tivoli Asset Management for IT, IBM SmartCloud Control Desk, and others.
Can unauthenticated users exploit CVE-2012-0728?
No, CVE-2012-0728 can only be exploited by remote authenticated users.
What type of vulnerability is CVE-2012-0728?
CVE-2012-0728 is an SQL injection vulnerability allowing attackers to execute arbitrary SQL queries.