CVE-2014-0849: Medium severity IBM Maximo Asset Management vulnerability
IBM Maximo Asset Management 7.x before 7.5.0.3 IFIX027 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allow remote authenticated users to gain privileges by leveraging membership in two security groups.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0849?
CVE-2014-0849 is classified with medium severity due to the potential for privilege escalation by authenticated users.
How do I fix CVE-2014-0849?
To fix CVE-2014-0849, upgrade to IBM Maximo Asset Management versions 7.5.0.3 or later and SmartCloud Control Desk versions 7.5.0.3 or later.
Who is affected by CVE-2014-0849?
CVE-2014-0849 affects users of IBM Maximo Asset Management versions 7.x prior to 7.5.0.3 and SmartCloud Control Desk versions 7.x prior to 7.5.0.3.
What types of accounts are exploited in CVE-2014-0849?
CVE-2014-0849 can be exploited by remote authenticated users who are members of two specific security groups.
Is there a workaround for CVE-2014-0849?
Currently, the recommended solution for CVE-2014-0849 is to update to the appropriate patched versions, as there are no reliable workarounds.