ZeroHour

CVE-2018-1524

CVSS 3.0
8.8 high
EPSS
2%p78
Published
()
Modified
Description

IBM Maximo Asset Management 7.6 through 7.6.3 installs with a default administrator account that a remote intruder could use to gain administrator access to the system. This vulnerability is due to an incomplete fix for CVE-2015-4966. IBM X-Force ID: 142116.

Vendors
ibm
Products
maximo asset management, maximo for aviation, maximo for life sciences, maximo for nuclear power, maximo for oil and gas, maximo for transportation, maximo for utilities, smartcloud control desk
Weakness
CWE-1188
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.