CVE-2015-4966: Medium severity ibm tivoli change and configuration management database vulnerability
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.9 FP009, and 7.6.0 before 7.6.0.2 IFIX001; Maximo Asset Management 7.5.0 before 7.5.0.9 FP009, 7.5.1, and 7.6.0 before 7.6.0.2 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products have a default administrator account, which makes it easier for remote authenticated users to obtain access via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4966?
CVE-2015-4966 has a medium severity rating due to its potential impact on exposed systems.
How do I fix CVE-2015-4966?
To fix CVE-2015-4966, you should upgrade to the patched versions of IBM Maximo Asset Management that are specified in the advisory.
What versions are affected by CVE-2015-4966?
CVE-2015-4966 affects multiple versions of IBM Maximo Asset Management, specifically versions 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.9, and 7.6.0 before 7.6.0.2.
Is CVE-2015-4966 actively exploited in the wild?
There is currently no confirmed evidence that CVE-2015-4966 is being actively exploited in the wild.
What are the potential impacts of CVE-2015-4966?
The potential impacts of CVE-2015-4966 include unauthorized access and manipulation of data in affected IBM Maximo Asset Management instances.