CVE-2015-7452

EUVD-2015-7376
IBM Maximo Asset Management 7.5 before 7.5.0.9 FP9 and 7.6 before 7.6.0.3 FP3 and Maximo Asset Management 7.5 before 7.5.0.9 FP9, 7.5.1, and 7.6 before 7.6.0.3 FP3 for SmartCloud Control Desk allow remote authenticated users to obtain sensitive information via the REST API.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 36%
Affected Products (NVD)
VendorProductVersion
ibmmaximo_asset_management
7.5
ibmmaximo_asset_management
7.6
ibmmaximo_asset_management_essentials
7.5
ibmmaximo_for_government
7.5
ibmmaximo_for_life_sciences
7.5
ibmmaximo_for_life_sciences
7.6
ibmmaximo_for_nuclear_power
7.5
ibmmaximo_for_oil_and_gas
7.5
ibmmaximo_for_transportation
7.5
ibmmaximo_for_utilities
7.5
ibmsmartcloud_control_desk
7.5
ibmsmartcloud_control_desk
7.6
𝑥
= Vulnerable software versions