CVE-2013-2998: Infoleak
frontcontroller.jsp in IBM Maximo Asset Management 7.x before 7.5.0.6 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allows remote authenticated users to obtain sensitive information via an invalid actioncode.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2998?
CVE-2013-2998 has a medium severity rating due to the potential disclosure of sensitive information.
How do I mitigate CVE-2013-2998?
To mitigate CVE-2013-2998, it is recommended to upgrade to the latest version of IBM Maximo Asset Management or SmartCloud Control Desk that addresses this vulnerability.
What versions are affected by CVE-2013-2998?
CVE-2013-2998 affects IBM Maximo Asset Management versions prior to 7.5.0.6 and SmartCloud Control Desk versions prior to 7.5.0.3.
Can CVE-2013-2998 be exploited remotely?
Yes, CVE-2013-2998 can be exploited by remote authenticated users to access sensitive information.
What causes the vulnerability CVE-2013-2998?
CVE-2013-2998 is caused by improper validation of the action_code parameter in the frontcontroller.jsp file.