CVE-2015-5016: Infoleak
IBM Maximo Asset Management 7.1, 7.5, and 7.6; Maximo Asset Management Essentials 7.1 and 7.5; Control Desk 7.5 and 7.6; Tivoli Asset Management for IT 7.1 and 7.2; and certain other IBM products allow remote authenticated users to bypass intended access restrictions and read arbitrary ticket worklog entries via unspecified vectors. IBM X-Force ID: 106460.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this IBM Maximo Asset Management vulnerability?
The vulnerability ID of this IBM Maximo Asset Management vulnerability is CVE-2015-5016.
What is the severity of CVE-2015-5016?
The severity of CVE-2015-5016 is medium.
Which versions of IBM Maximo Asset Management are affected by CVE-2015-5016?
Versions 7.1, 7.5, and 7.6 of IBM Maximo Asset Management are affected by CVE-2015-5016.
How can a remote authenticated user exploit CVE-2015-5016?
A remote authenticated user can exploit CVE-2015-5016 to bypass intended access restrictions and read arbitrary ticket workloads.
Where can I find more information about CVE-2015-5016?
You can find more information about CVE-2015-5016 [here](http://www-01.ibm.com/support/docview.wss?uid=swg21971160) and [here](https://exchange.xforce.ibmcloud.com/vulnerabilities/106460).