Lucene search

K
cve[email protected]CVE-2012-6356
HistoryFeb 20, 2013 - 12:09 p.m.

CVE-2012-6356

2013-02-2012:09:22
CWE-264
web.nvd.nist.gov
23
ibm
maximo asset management
smartcloud control desk
cve-2012-6356
import operation
security vulnerability

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

6.5 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

59.7%

IBM Maximo Asset Management 7.5, Maximo Asset Management Essentials 7.5, and SmartCloud Control Desk 7.5 allow remote authenticated users to gain privileges via vectors related to an import operation.

Affected configurations

NVD
Node
ibmmaximo_asset_managementMatch7.5.0.0
OR
ibmmaximo_asset_management_essentialsMatch7.5.0.0
OR
ibmsmartcloud_control_deskMatch7.5.0.0

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

6.5 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

59.7%

Related for CVE-2012-6356