CVE-2015-5016

IBM Maximo Asset Management 7.1, 7.5, and 7.6; Maximo Asset Management Essentials 7.1 and 7.5; Control Desk 7.5 and 7.6; Tivoli Asset Management for IT 7.1 and 7.2; and certain other IBM products allow remote authenticated users to bypass intended access restrictions and read arbitrary ticket worklog entries via unspecified vectors. IBM X-Force ID: 106460.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
ibmCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 29%
VendorProductVersion
ibmmaximo_asset_management
7.1
ibmmaximo_asset_management
7.5
ibmmaximo_asset_management
7.6
ibmmaximo_asset_management_essentials
7.1
ibmmaximo_asset_management_essentials
7.5
ibmmaximo_for_energy_optimization
7.1
ibmmaximo_for_aviation
7.6
ibmmaximo_for_government
7.1
ibmmaximo_for_government
7.5
ibmmaximo_for_nuclear_power
7.1
ibmmaximo_for_nuclear_power
7.5
ibmmaximo_for_transportation
7.1
ibmmaximo_for_transportation
7.5
ibmmaximo_for_transportation
7.6
ibmmaximo_for_life_sciences
7.1
ibmmaximo_for_life_sciences
7.5
ibmmaximo_for_life_sciences
7.6
ibmmaximo_for_oil_and_gas
7.1
ibmmaximo_for_oil_and_gas
7.5
ibmmaximo_for_utilities
7.1
ibmmaximo_for_utilities
7.5
ibmcontrol_desk
7.5
ibmcontrol_desk
7.6
ibmtivoli_asset_management_for_it
7.1
ibmtivoli_asset_management_for_it
7.2
ibmtivoli_service_request_manager
7.1
ibmtivoli_service_request_manager
7.2
ibmchange_and_configuration_management_database
7.1
ibmchange_and_configuration_management_database
7.2
𝑥
= Vulnerable software versions