Vulnerability Name: | CVE-2012-0727 (CCN-74306) | ||||||||
Assigned: | 2012-09-04 | ||||||||
Published: | 2012-09-04 | ||||||||
Updated: | 2017-08-29 | ||||||||
Summary: | SQL injection vulnerability in IBM Maximo Asset Management 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | ||||||||
CVSS v3 Severity: | 5.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 6.5 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P) 5.7 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P/E:H/RL:OF/RC:C)
5.7 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-89 | ||||||||
Vulnerability Consequences: | Data Manipulation | ||||||||
References: | Source: MITRE Type: CNA CVE-2012-0727 Source: CCN Type: SA50551 IBM Maximo Asset Management Products Multiple Vulnerabilities Source: SECUNIA Type: Vendor Advisory 50551 Source: AIXAPAR Type: UNKNOWN IV17963 Source: CCN Type: IBM Security Bulletin 1610081 Security Vulnerabilities Addressed in Asset and Service Mgmt Source: CONFIRM Type: UNKNOWN http://www-01.ibm.com/support/docview.wss?uid=swg21610081 Source: CCN Type: OSVDB ID: 85178 IBM Multiple Product Unspecified SQL Injection (2012-0727) Source: XF Type: UNKNOWN multiple-ibm-configure-sql-injection(74306) Source: XF Type: UNKNOWN ibm-maximo-sql-injection-iv17963(74306) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |