First published: Mon May 26 2014(Updated: )
IBM Maximo Asset Management 7.5.x before 7.5.0.3 IFIX027, 7.5.0.4 before IFIX011, and 7.5.0.5 before IFIX006 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allow remote authenticated users to bypass intended access restrictions, and modify physical counts associated with restricted storerooms, via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Maximo Asset Management | =7.5.0.0 | |
IBM Maximo Asset Management | =7.5.0.1 | |
IBM Maximo Asset Management | =7.5.0.2 | |
IBM Maximo Asset Management | =7.5.0.3 | |
IBM Maximo Asset Management | =7.5.0.4 | |
IBM Maximo Asset Management | =7.5.0.5 | |
IBM Control Desk | =7.0 | |
IBM Control Desk | =7.5 | |
IBM Control Desk | =7.5.0.0 | |
IBM Control Desk | =7.5.0.1 | |
IBM Control Desk | =7.5.0.2 | |
IBM Control Desk | =7.5.1.0 | |
IBM Control Desk | =7.5.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5464 is classified as a moderate severity vulnerability due to its ability to allow remote authenticated users to bypass access restrictions.
To fix CVE-2013-5464, upgrade IBM Maximo Asset Management to version 7.5.0.3 IFIX027 or higher, and IBM SmartCloud Control Desk to version 7.5.0.3 or higher.
CVE-2013-5464 allows remote authenticated users to bypass intended access restrictions and modify physical counts.
Affected versions include IBM Maximo Asset Management 7.5.0.0, 7.5.0.1, 7.5.0.2, and prior to 7.5.0.3 IFIX027.
Affected versions include IBM SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2.