CVE-2013-5460: Low severity IBM Maximo Asset Management vulnerability
IBM Maximo Asset Management 7.x before 7.5.0.6 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allow remote authenticated users to bypass intended access restrictions, and read communication logs associated with unrelated records, via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-5460?
CVE-2013-5460 has a medium severity because it allows remote authenticated users to bypass access restrictions.
How do I fix CVE-2013-5460?
To fix CVE-2013-5460, upgrade IBM Maximo Asset Management to version 7.5.0.6 or higher, or IBM SmartCloud Control Desk to version 7.5.0.3 or higher.
Who is affected by CVE-2013-5460?
CVE-2013-5460 affects users of IBM Maximo Asset Management versions prior to 7.5.0.6 and IBM SmartCloud Control Desk versions prior to 7.5.0.3.
What type of vulnerability is CVE-2013-5460?
CVE-2013-5460 is an access control vulnerability that allows unauthorized access to communication logs.
Can CVE-2013-5460 be exploited remotely?
Yes, CVE-2013-5460 can be exploited by remote authenticated users.