IBM SmartCloud Control Desk 7.6.0.1

CPE Details

IBM SmartCloud Control Desk 7.6.0.1
7.6.0.1
2016-03-21
19h22 +00:00
2021-06-08
11h28 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:ibm:smartcloud_control_desk:7.6.0.1:*:*:*:*:*:*:*

Informations

Vendor

ibm

Product

smartcloud_control_desk

Version

7.6.0.1

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2019-4486 2019-10-24 12h00 +00:00 IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 164070.
5.4
Medium
CVE-2018-1528 2018-08-06 14h00 +00:00 IBM Maximo Asset Management 7.6 through 7.6.3 could allow an authenticated user to obtain sensitive information from the WhoAmI API. IBM X-Force ID: 142290.
4.3
Medium
CVE-2018-1524 2018-08-03 15h00 +00:00 IBM Maximo Asset Management 7.6 through 7.6.3 installs with a default administrator account that a remote intruder could use to gain administrator access to the system. This vulnerability is due to an incomplete fix for CVE-2015-4966. IBM X-Force ID: 142116.
8.8
High
CVE-2015-7448 2016-03-12 14h00 +00:00 SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.9 IFIX003, and 7.6.0 before 7.6.0.3 IFIX001; Maximo Asset Management 7.5.0 before 7.5.0.9 IFIX003, 7.5.1, and 7.6.0 before 7.6.0.3 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
5.4
Medium