First published: Fri Aug 29 2014(Updated: )
IBM Maximo Asset Management 6.1 through 6.5, 7.1 through 7.1.1.13, and 7.5 through 7.5.0.6; Maximo Asset Management 7.5.0 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk; and Maximo Asset Management 6.2.8, 7.1, and 7.2 for Tivoli IT Asset Management for IT and certain other products allow remote authenticated users to bypass intended write-access restrictions on calendar entries via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Maximo Asset Management | =6.1 | |
IBM Maximo Asset Management | =6.2 | |
IBM Maximo Asset Management | =6.2.1 | |
IBM Maximo Asset Management | =6.2.2 | |
IBM Maximo Asset Management | =6.2.3 | |
IBM Maximo Asset Management | =6.2.4 | |
IBM Maximo Asset Management | =6.2.5 | |
IBM Maximo Asset Management | =6.2.6 | |
IBM Maximo Asset Management | =6.2.6.1 | |
IBM Maximo Asset Management | =6.2.7 | |
IBM Maximo Asset Management | =6.2.8 | |
IBM Maximo Asset Management | =6.5 | |
IBM Maximo Asset Management | =7.1 | |
IBM Maximo Asset Management | =7.1.1 | |
IBM Maximo Asset Management | =7.1.1.1 | |
IBM Maximo Asset Management | =7.1.1.2 | |
IBM Maximo Asset Management | =7.1.1.5 | |
IBM Maximo Asset Management | =7.1.1.6 | |
IBM Maximo Asset Management | =7.1.1.7 | |
IBM Maximo Asset Management | =7.1.1.8 | |
IBM Maximo Asset Management | =7.1.1.9 | |
IBM Maximo Asset Management | =7.1.1.10 | |
IBM Maximo Asset Management | =7.1.1.11 | |
IBM Maximo Asset Management | =7.1.1.12 | |
IBM Maximo Asset Management | =7.1.1.13 | |
IBM Maximo Asset Management | =7.1.2 | |
IBM Maximo Asset Management | =7.5.0.0 | |
IBM Maximo Asset Management | =7.5.0.1 | |
IBM Maximo Asset Management | =7.5.0.2 | |
IBM Maximo Asset Management | =7.5.0.3 | |
IBM Maximo Asset Management | =7.5.0.4 | |
IBM Maximo Asset Management | =7.5.0.5 | |
IBM Maximo Asset Management | =7.5.0.6 | |
IBM Control Desk | =7.0 | |
IBM Control Desk | =7.5 | |
IBM Control Desk | =7.5.0.0 | |
IBM Control Desk | =7.5.0.1 | |
IBM Control Desk | =7.5.0.2 | |
IBM Control Desk | =7.5.0.3 | |
IBM Control Desk | =7.5.1.0 | |
IBM Control Desk | =7.5.1.1 | |
IBM Control Desk | =7.5.1.2 | |
IBM Tivoli IT Asset Management for IT | =6.2 | |
IBM Tivoli IT Asset Management for IT | =7.1 | |
IBM Tivoli IT Asset Management for IT | =7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3084 is rated as a moderate severity vulnerability.
To fix CVE-2014-3084, update the IBM Maximo Asset Management to the latest version as specified by IBM.
CVE-2014-3084 affects IBM Maximo Asset Management versions 6.1 through 6.5, 7.1 through 7.1.1.13, and 7.5 through 7.5.0.6 among others.
CVE-2014-3084 may allow an attacker to perform unauthorized actions on compromised systems.
No specific workarounds were provided for CVE-2014-3084; the recommended measure is to apply the available patches.