Lucene search

K
cve[email protected]CVE-2013-3323
HistoryFeb 18, 2020 - 5:15 p.m.

CVE-2013-3323

2020-02-1817:15:12
CWE-269
web.nvd.nist.gov
34
ibm maximo
asset management
privilege escalation
vulnerability
webseal
basic authentication
nvd
cve-2013-3323

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.2 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

73.5%

A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 7.5, 7.1, and 6.2, when WebSeal with Basic Authentication is used, due to a failure to invalidate the authentication session, which could let a malicious user obtain unauthorized access.

Affected configurations

NVD
Node
ibmchange_and_configuration_management_databaseMatch7.1
OR
ibmchange_and_configuration_management_databaseMatch7.2
OR
ibmmaximo_asset_managementMatch6.2
OR
ibmmaximo_asset_managementMatch7.1
OR
ibmmaximo_asset_managementMatch7.5
OR
ibmmaximo_asset_management_essentialsMatch6.2
OR
ibmmaximo_asset_management_essentialsMatch7.1
OR
ibmmaximo_asset_management_essentialsMatch7.5
OR
ibmmaximo_for_governmentMatch6.2
OR
ibmmaximo_for_governmentMatch7.1
OR
ibmmaximo_for_governmentMatch7.5
OR
ibmmaximo_for_life_sciencesMatch6.2
OR
ibmmaximo_for_life_sciencesMatch6.4
OR
ibmmaximo_for_life_sciencesMatch6.5
OR
ibmmaximo_for_life_sciencesMatch7.1
OR
ibmmaximo_for_life_sciencesMatch7.5
OR
ibmmaximo_for_nuclear_powerMatch6.2
OR
ibmmaximo_for_nuclear_powerMatch6.3
OR
ibmmaximo_for_nuclear_powerMatch7.1
OR
ibmmaximo_for_nuclear_powerMatch7.5
OR
ibmmaximo_for_oil_and_gasMatch6.2
OR
ibmmaximo_for_oil_and_gasMatch6.3
OR
ibmmaximo_for_oil_and_gasMatch6.4
OR
ibmmaximo_for_oil_and_gasMatch7.1
OR
ibmmaximo_for_oil_and_gasMatch7.5
OR
ibmmaximo_for_transportationMatch6.2
OR
ibmmaximo_for_transportationMatch6.3
OR
ibmmaximo_for_transportationMatch7.1
OR
ibmmaximo_for_transportationMatch7.5
OR
ibmmaximo_for_utilitiesMatch6.2
OR
ibmmaximo_for_utilitiesMatch6.3
OR
ibmmaximo_for_utilitiesMatch7.1
OR
ibmmaximo_for_utilitiesMatch7.5
OR
ibmmaximo_service_deskMatch6.2
OR
ibmsmartcloud_control_deskMatch7.5
OR
ibmtivoli_asset_management_for_itMatch6.2
OR
ibmtivoli_asset_management_for_itMatch7.1
OR
ibmtivoli_asset_management_for_itMatch7.2
OR
ibmtivoli_service_request_managerMatch7.1
OR
ibmtivoli_service_request_managerMatch7.2

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.2 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

73.5%

Related for CVE-2013-3323