First published: Sat Jan 02 2016(Updated: )
IBM Maximo Asset Management 7.5 before 7.5.0.9 FP9 and 7.6 before 7.6.0.3 FP3 and Maximo Asset Management 7.5 before 7.5.0.9 FP9, 7.5.1, and 7.6 before 7.6.0.3 FP3 for SmartCloud Control Desk allow remote authenticated users to obtain sensitive information via the REST API.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Maximo Asset Management | =7.5 | |
IBM Maximo Asset Management | =7.6 | |
Ibm Maximo Asset Management Essentials | =7.5 | |
Ibm Maximo For Government | =7.5 | |
Ibm Maximo For Life Sciences | =7.5 | |
Ibm Maximo For Life Sciences | =7.6 | |
Ibm Maximo For Nuclear Power | =7.5 | |
Ibm Maximo For Oil And Gas | =7.5 | |
Ibm Maximo For Transportation | =7.5 | |
Ibm Maximo For Utilities | =7.5 | |
IBM SmartCloud Control Desk | =7.5 | |
IBM SmartCloud Control Desk | =7.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7452 is classified as a medium severity vulnerability.
To fix CVE-2015-7452, upgrade IBM Maximo Asset Management and SmartCloud Control Desk to the latest patched versions.
CVE-2015-7452 affects IBM Maximo Asset Management versions 7.5 and 7.6, as well as IBM SmartCloud Control Desk versions 7.5 and 7.6.
CVE-2015-7452 can be exploited by remote authenticated users to gain unauthorized access to sensitive information via the REST API.
Yes, CVE-2015-7452 remains a concern for users who have not updated to the fixed versions since it allows exposure of sensitive data.