CVE-2013-5464
IBM Maximo Asset Management 7.5.x before 7.5.0.3 IFIX027, 7.5.0.4 before IFIX011, and 7.5.0.5 before IFIX006 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allow remote authenticated users to bypass intended access…
Does this matter?
Lower severity and a low EPSS score (1.06%). Track it; it rarely justifies an emergency change on its own.
Description
IBM Maximo Asset Management 7.5.x before 7.5.0.3 IFIX027, 7.5.0.4 before IFIX011, and 7.5.0.5 before IFIX006 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allow remote authenticated users to bypass intended access restrictions, and modify physical counts associated with restricted storerooms, via unspecified vectors.
- CVSS 2.0
- 6.0 MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
- EPSS
- 1.06% probability · 63th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- ibm/maximo asset management · ibm/smartcloud control desk
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV46277
- http://www-01.ibm.com/support/docview.wss?uid=swg21670870Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/88362
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV46277
- http://www-01.ibm.com/support/docview.wss?uid=swg21670870Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/88362
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.