CVE Vulnerabilities

CVE-2013-3323

Improper Privilege Management

Published: Feb 18, 2020 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 7.5, 7.1, and 6.2, when WebSeal with Basic Authentication is used, due to a failure to invalidate the authentication session, which could let a malicious user obtain unauthorized access.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
Change_and_configuration_management_databaseIbm7.1 (including)7.1 (including)
Change_and_configuration_management_databaseIbm7.2 (including)7.2 (including)
Maximo_asset_managementIbm6.2 (including)6.2 (including)
Maximo_asset_managementIbm7.1 (including)7.1 (including)
Maximo_asset_managementIbm7.5 (including)7.5 (including)
Maximo_asset_management_essentialsIbm6.2 (including)6.2 (including)
Maximo_asset_management_essentialsIbm7.1 (including)7.1 (including)
Maximo_asset_management_essentialsIbm7.5 (including)7.5 (including)
Maximo_for_governmentIbm6.2 (including)6.2 (including)
Maximo_for_governmentIbm7.1 (including)7.1 (including)
Maximo_for_governmentIbm7.5 (including)7.5 (including)
Maximo_for_life_sciencesIbm6.2 (including)6.2 (including)
Maximo_for_life_sciencesIbm6.4 (including)6.4 (including)
Maximo_for_life_sciencesIbm6.5 (including)6.5 (including)
Maximo_for_life_sciencesIbm7.1 (including)7.1 (including)
Maximo_for_life_sciencesIbm7.5 (including)7.5 (including)
Maximo_for_nuclear_powerIbm6.2 (including)6.2 (including)
Maximo_for_nuclear_powerIbm6.3 (including)6.3 (including)
Maximo_for_nuclear_powerIbm7.1 (including)7.1 (including)
Maximo_for_nuclear_powerIbm7.5 (including)7.5 (including)
Maximo_for_oil_and_gasIbm6.2 (including)6.2 (including)
Maximo_for_oil_and_gasIbm6.3 (including)6.3 (including)
Maximo_for_oil_and_gasIbm6.4 (including)6.4 (including)
Maximo_for_oil_and_gasIbm7.1 (including)7.1 (including)
Maximo_for_oil_and_gasIbm7.5 (including)7.5 (including)
Maximo_for_transportationIbm6.2 (including)6.2 (including)
Maximo_for_transportationIbm6.3 (including)6.3 (including)
Maximo_for_transportationIbm7.1 (including)7.1 (including)
Maximo_for_transportationIbm7.5 (including)7.5 (including)
Maximo_for_utilitiesIbm6.2 (including)6.2 (including)
Maximo_for_utilitiesIbm6.3 (including)6.3 (including)
Maximo_for_utilitiesIbm7.1 (including)7.1 (including)
Maximo_for_utilitiesIbm7.5 (including)7.5 (including)
Maximo_service_deskIbm6.2 (including)6.2 (including)
Smartcloud_control_deskIbm7.5 (including)7.5 (including)
Tivoli_asset_management_for_itIbm6.2 (including)6.2 (including)
Tivoli_asset_management_for_itIbm7.1 (including)7.1 (including)
Tivoli_asset_management_for_itIbm7.2 (including)7.2 (including)
Tivoli_service_request_managerIbm7.1 (including)7.1 (including)
Tivoli_service_request_managerIbm7.2 (including)7.2 (including)

Potential Mitigations

References