Description
IBM Maximo Asset Management 7.6.0, and 7.6.1 could allow an authenticated user to obtain highly sensitive information that they should not normally have access to. IBM X-Force ID: 163998.
CVSS breakdown
CVSS 3.0
Availability
None
Attack Vector
Network
Integrity
None
Scope
Unchanged
User Interaction
None
Attack Complexity
Low
Confidentiality
High
Privileges Required
Low
RL
O
E
Unchanged
RC
Changed
Affected products
- ibm / maximo_asset_management7.6.0 – 7.6.0
- ibm / maximo_asset_management7.6.1 – 7.6.1
- ibm / maximo_asset_management7.6.1.1 – 7.6.1.1