CVE-2015-7395: Medium severity ibm tivoli change and configuration management database vulnerability
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX005, and 7.6.0 before 7.6.0.2 FP002; Maximo Asset Management 7.5.0 before 7.5.0.8 IFIX005, 7.5.1, and 7.6.0 before 7.6.0.2 FP002 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products allow remote authenticated users to bypass intended work-order change restrictions via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7395?
The CVE-2015-7395 vulnerability is rated as a moderate severity issue.
How do I fix CVE-2015-7395?
To remediate CVE-2015-7395, you should upgrade to the latest fixed version of IBM Maximo Asset Management, specifically versions 7.5.0.8 or 7.6.0.2 and above.
What versions of IBM Maximo Asset Management are affected by CVE-2015-7395?
CVE-2015-7395 affects IBM Maximo Asset Management versions 7.1 through 7.1.1.13, 7.5.0 prior to 7.5.0.8 IFIX005, and 7.6.0 prior to 7.6.0.2 FP002.
Is CVE-2015-7395 related to any other IBM products?
Yes, this vulnerability also affects IBM SmartCloud Control Desk and IBM Tivoli Asset Management for IT in specific versions.
Can exploit attempts targeting CVE-2015-7395 lead to data loss?
Yes, successful exploitation of CVE-2015-7395 may lead to unauthorized access and potential data loss.