Lucene search

K
cve[email protected]CVE-2012-6357
HistoryFeb 20, 2013 - 12:09 p.m.

CVE-2012-6357

2013-02-2012:09:22
CWE-264
web.nvd.nist.gov
14
ibm
maximo
asset management
smartcloud control desk
cve-2012-6357
nvd
security
privileges
bypass

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

6.6 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

59.7%

IBM Maximo Asset Management 7.5, Maximo Asset Management Essentials 7.5, and SmartCloud Control Desk 7.5 allow remote authenticated users to gain privileges and bypass intended restrictions on asset-lookup operations via unspecified vectors.

Affected configurations

NVD
Node
ibmmaximo_asset_managementMatch7.5.0.0
OR
ibmmaximo_asset_management_essentialsMatch7.5.0.0
OR
ibmsmartcloud_control_deskMatch7.5.0.0

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

6.6 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

59.7%

Related for CVE-2012-6357