CVE-2015-7396: Medium severity ibm maximo asset management vulnerability
The Scheduler in IBM Maximo Asset Management 7.5 before 7.5.0.8 IF6 and 7.6 before 7.6.0.1 FP1 and Maximo Asset Management 7.5 before 7.5.0.8 IF6, 7.5.1, and 7.6 before 7.6.0.1 FP1 for SmartCloud Control Desk allows remote authenticated users to bypass intended access restrictions, and obtain sensitive information or modify data, via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7396?
CVE-2015-7396 is classified as a medium severity vulnerability.
How do I fix CVE-2015-7396?
To remediate CVE-2015-7396, you should upgrade to IBM Maximo Asset Management versions 7.5.0.8 IF6, 7.6.0.1 FP1, or later.
Which software versions are affected by CVE-2015-7396?
CVE-2015-7396 affects IBM Maximo Asset Management versions 7.5 and 7.6 and their related products prior to specified patches.
What type of vulnerability is CVE-2015-7396?
CVE-2015-7396 is an access control vulnerability that allows remote authenticated users to bypass intended access restrictions.
Who is impacted by CVE-2015-7396?
Organizations using affected versions of IBM Maximo Asset Management and related software could be impacted by CVE-2015-7396.