Vulnerability Description
The Scheduler in IBM Maximo Asset Management 7.5 before 7.5.0.8 IF6 and 7.6 before 7.6.0.1 FP1 and Maximo Asset Management 7.5 before 7.5.0.8 IF6, 7.5.1, and 7.6 before 7.6.0.1 FP1 for SmartCloud Control Desk allows remote authenticated users to bypass intended access restrictions, and obtain sensitive information or modify data, via unspecified vectors.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Maximo Asset Management | 7.5 |
| Ibm | Maximo Asset Management Essentials | 7.5 |
| Ibm | Maximo For Government | 7.5 |
| Ibm | Maximo For Life Sciences | 7.5 |
| Ibm | Maximo For Nuclear Power | 7.5 |
| Ibm | Maximo For Oil And Gas | 7.5 |
| Ibm | Maximo For Transportation | 7.5 |
| Ibm | Maximo For Utilities | 7.5 |
| Ibm | Smartcloud Control Desk | 7.5 |
Related Weaknesses (CWE)
References
- http://www-01.ibm.com/support/docview.wss?uid=swg21970799Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21970799Vendor Advisory
FAQ
What is CVE-2015-7396?
CVE-2015-7396 is a vulnerability with a CVSS score of 5.4 (MEDIUM). The Scheduler in IBM Maximo Asset Management 7.5 before 7.5.0.8 IF6 and 7.6 before 7.6.0.1 FP1 and Maximo Asset Management 7.5 before 7.5.0.8 IF6, 7.5.1, and 7.6 before 7.6.0.1 FP1 for SmartCloud Cont...
How severe is CVE-2015-7396?
CVE-2015-7396 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-7396?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Maximo Asset Management, Ibm Maximo Asset Management Essentials, Ibm Maximo For Government, Ibm Maximo For Life Sciences, Ibm Maximo For Nuclear Power.