CVE-2013-4016: SQL Injection
SQL injection vulnerability in IBM Maximo Asset Management 7.x before 7.1.1.7 LAFIX.20140319-0837, 7.1.1.11 before IFIX.20140323-0749, 7.1.1.12 before IFIX.20140321-1336, 7.5.x before 7.5.0.3 IFIX027, 7.5.0.4 before IFIX011, and 7.5.0.5 before IFIX006; SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2; and Tivoli IT Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB) 7.x before 7.1.1.7 LAFIX.20140319-0837, 7.1.1.11 before IFIX.20140207-1801, and 7.1.1.12 before IFIX.20140218-1510 allows remote authenticated users to execute arbitrary SQL commands via a Birt report with a WHERE clause in plain text.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4016?
CVE-2013-4016 is classified as a medium severity SQL injection vulnerability.
Which versions of IBM Maximo Asset Management are affected by CVE-2013-4016?
CVE-2013-4016 affects IBM Maximo Asset Management versions prior to 7.1.1.7 and 7.5.0.3.
How do I fix CVE-2013-4016?
To resolve CVE-2013-4016, you should upgrade the affected software to a patched version as recommended by IBM.
What kind of attack can exploit CVE-2013-4016?
CVE-2013-4016 can be exploited to perform SQL injection attacks, potentially allowing unauthorized access to the database.
Is there a security patch available for CVE-2013-4016?
Yes, IBM has released security patches for versions impacted by CVE-2013-4016.