Medium severity5.4NVD Advisory· Published Jan 2, 2016· Updated Jun 17, 2026
CVE-2015-7451
CVE-2015-7451
Description
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5 before 7.5.0.9 IF2 and 7.6 before 7.6.0.3 FP3 and Maximo Asset Management 7.5 before 7.5.0.9 IF2, 7.5.1, and 7.6 before 7.6.0.3 FP3 for SmartCloud Control Desk allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
14cpe:2.3:a:ibm:maximo_asset_management:7.5:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:ibm:maximo_asset_management:7.5:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:maximo_asset_management:7.6:*:*:*:*:*:*:*
- (no CPE)range: 7.5 <7.5.0.9 IF2; 7.6 <7.6.0.3 FP3
- cpe:2.3:a:ibm:maximo_asset_management_essentials:7.5:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:maximo_for_government:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:maximo_for_life_sciences:7.5:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:ibm:maximo_for_life_sciences:7.5:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:maximo_for_life_sciences:7.6:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:maximo_for_nuclear_power:7.5:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:maximo_for_oil_and_gas:7.5:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:maximo_for_transportation:7.5:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:maximo_for_utilities:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:smartcloud_control_desk:7.5:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:ibm:smartcloud_control_desk:7.5:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:smartcloud_control_desk:7.6:*:*:*:*:*:*:*
- (no CPE)range: 7.5 <7.5.0.9 IF2; 7.6 <7.6.0.3 FP3
Patches
Vulnerability mechanics
References
1- www-01.ibm.com/support/docview.wssnvdVendor Advisory
News mentions
0No linked articles in our index yet.