CVE-2014-6102: Low severity ibm tivoli change and configuration management database vulnerability
IBM Maximo Asset Management 7.1 through 7.1.1.13 and 7.5.0 before 7.5.0.6 IFIX008, Maximo Asset Management 7.5.0 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk, and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products do not properly handle logout actions, which allows remote attackers to bypass intended Cognos BI Direct Integration access restrictions by leveraging an unattended workstation.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6102?
CVE-2014-6102 has a high severity rating due to its potential to allow unauthorized access to sensitive data.
How do I fix CVE-2014-6102?
To fix CVE-2014-6102, upgrade to IBM Maximo Asset Management versions 7.5.0.6 or later.
Which IBM products are affected by CVE-2014-6102?
CVE-2014-6102 affects IBM Maximo Asset Management 7.1, 7.5.0 before 7.5.0.6, and Tivoli Asset Management for IT among others.
Is there a workaround for CVE-2014-6102?
There are no known workarounds for CVE-2014-6102 other than upgrading to the patched versions.
What type of vulnerability is CVE-2014-6102 classified as?
CVE-2014-6102 is classified as an authorization vulnerability.