CVE-2014-3084: Medium severity ibm maximo asset management vulnerability
IBM Maximo Asset Management 6.1 through 6.5, 7.1 through 7.1.1.13, and 7.5 through 7.5.0.6; Maximo Asset Management 7.5.0 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk; and Maximo Asset Management 6.2.8, 7.1, and 7.2 for Tivoli IT Asset Management for IT and certain other products allow remote authenticated users to bypass intended write-access restrictions on calendar entries via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3084?
CVE-2014-3084 is rated as a moderate severity vulnerability.
How do I fix CVE-2014-3084?
To fix CVE-2014-3084, update the IBM Maximo Asset Management to the latest version as specified by IBM.
What versions are affected by CVE-2014-3084?
CVE-2014-3084 affects IBM Maximo Asset Management versions 6.1 through 6.5, 7.1 through 7.1.1.13, and 7.5 through 7.5.0.6 among others.
What impact does CVE-2014-3084 have on IBM Maximo Asset Management?
CVE-2014-3084 may allow an attacker to perform unauthorized actions on compromised systems.
Is there a workaround for CVE-2014-3084?
No specific workarounds were provided for CVE-2014-3084; the recommended measure is to apply the available patches.