6.5
CVSSv2

CVE-2013-4016

Published: 26/05/2014 Updated: 29/08/2017
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in IBM Maximo Asset Management 7.x prior to 7.1.1.7 LAFIX.20140319-0837, 7.1.1.11 before IFIX.20140323-0749, 7.1.1.12 before IFIX.20140321-1336, 7.5.x prior to 7.5.0.3 IFIX027, 7.5.0.4 before IFIX011, and 7.5.0.5 before IFIX006; SmartCloud Control Desk 7.x prior to 7.5.0.3 and 7.5.1.x prior to 7.5.1.2; and Tivoli IT Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB) 7.x prior to 7.1.1.7 LAFIX.20140319-0837, 7.1.1.11 before IFIX.20140207-1801, and 7.1.1.12 before IFIX.20140218-1510 allows remote authenticated users to execute arbitrary SQL commands via a Birt report with a WHERE clause in plain text.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm tivoli service request manager 7.1.1.12

ibm maximo service desk 7.1.1.7

ibm tivoli it asset management for it 7.1.1.7

ibm tivoli it asset management for it 7.1.1.11

ibm change and configuration management database 7.1.1.7

ibm change and configuration management database 7.1.1.11

ibm tivoli it asset management for it 7.1.1.12

ibm tivoli service request manager 7.1.1.7

ibm tivoli service request manager 7.1.1.11

ibm change and configuration management database 7.1.1.12

ibm tivoli service request manager 7.1.1

ibm maximo service desk 7.1.1.11

ibm maximo service desk 7.1.1.12

ibm tivoli asset management for it 7.0

ibm tivoli asset management for it 7.1

ibm smartcloud control desk 7.5

ibm smartcloud control desk 7.5.0.0

ibm smartcloud control desk 7.5.1.0

ibm smartcloud control desk 7.5.1.1

ibm smartcloud control desk 7.0

ibm smartcloud control desk 7.5.0.1

ibm smartcloud control desk 7.5.0.2

ibm maximo asset management 7.5.0.0

ibm maximo asset management 7.5.0.4

ibm maximo asset management 7.5.0.5

ibm maximo asset management 7.5.0.1

ibm maximo asset management 7.5.0.2

ibm maximo asset management 7.5.0.3

ibm maximo asset management 7.1.1.12

ibm maximo asset management 7.1

ibm maximo asset management 7.1.1.2

ibm maximo asset management 7.1.1.5

ibm maximo asset management 7.1.1

ibm maximo asset management 7.1.1.1

ibm maximo asset management 7.1.1.11

ibm maximo asset management 7.1.1.6

ibm maximo asset management 7.1.1.7