Product:

Smartcloud_control_desk

(Ibm)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 65
Date Id Summary Products Score Patch Annotated
2014-05-26 CVE-2013-2998 frontcontroller.jsp in IBM Maximo Asset Management 7.x before 7.5.0.6 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allows remote authenticated users to obtain sensitive information via an invalid action_code. Maximo_asset_management, Smartcloud_control_desk N/A
2013-02-20 CVE-2013-0457 Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5, Maximo Asset Management Essentials 7.5, and SmartCloud Control Desk 7.5 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to a uisessionid. Maximo_asset_management, Maximo_asset_management_essentials, Smartcloud_control_desk N/A
2013-02-20 CVE-2012-6357 IBM Maximo Asset Management 7.5, Maximo Asset Management Essentials 7.5, and SmartCloud Control Desk 7.5 allow remote authenticated users to gain privileges and bypass intended restrictions on asset-lookup operations via unspecified vectors. Maximo_asset_management, Maximo_asset_management_essentials, Smartcloud_control_desk N/A
2013-02-20 CVE-2012-6356 IBM Maximo Asset Management 7.5, Maximo Asset Management Essentials 7.5, and SmartCloud Control Desk 7.5 allow remote authenticated users to gain privileges via vectors related to an import operation. Maximo_asset_management, Maximo_asset_management_essentials, Smartcloud_control_desk N/A
2013-02-20 CVE-2012-6355 IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivoli Service Request Manager 7.1 and 7.2, Maximo Service Desk 6.2, Change and Configuration Management Database (CCMDB) 7.1 and 7.2, and SmartCloud Control Desk 7.5 allow remote authenticated users to gain privileges via vectors related to a work order. Change_and_configuration_management_database, Maximo_asset_management, Maximo_asset_management_essentials, Maximo_service_desk, Smartcloud_control_desk, Tivoli_asset_management_for_it, Tivoli_service_request_manager N/A
2014-05-26 CVE-2012-3333 CRLF injection vulnerability in IBM Maximo Asset Management 7.x before 7.5.0.6 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted parameter in a URL. Maximo_asset_management, Smartcloud_control_desk N/A
2013-02-20 CVE-2012-3327 Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivoli Service Request Manager 7.1 and 7.2, Maximo Service Desk 6.2, Change and Configuration Management Database (CCMDB) 7.1 and 7.2, and SmartCloud Control Desk 7.5 allows remote attackers to inject arbitrary web script or HTML via vectors related to a login action. Change_and_configuration_management_database, Maximo_asset_management, Maximo_asset_management_essentials, Maximo_service_desk, Smartcloud_control_desk, Tivoli_asset_management_for_it, Tivoli_service_request_manager N/A
2012-09-10 CVE-2012-3326 Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Change_and_configuration_management_database, Maximo_asset_management, Maximo_service_desk, Smartcloud_control_desk, Tivoli_asset_management_for_it, Tivoli_service_request_manager N/A
2013-02-20 CVE-2012-3322 Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivoli Service Request Manager 7.1 and 7.2, Maximo Service Desk 6.2, Change and Configuration Management Database (CCMDB) 7.1 and 7.2, and SmartCloud Control Desk 7.5 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to a display name. Change_and_configuration_management_database, Maximo_asset_management, Maximo_asset_management_essentials, Maximo_service_desk, Smartcloud_control_desk, Tivoli_asset_management_for_it, Tivoli_service_request_manager N/A
2013-02-20 CVE-2012-3321 IBM SmartCloud Control Desk 7.5 allows remote authenticated users to bypass intended access restrictions via vectors involving an expired password. Smartcloud_control_desk N/A