Medium severity5.4NVD Advisory· Published Jan 2, 2016· Updated May 6, 2026
CVE-2015-7451
CVE-2015-7451
Description
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5 before 7.5.0.9 IF2 and 7.6 before 7.6.0.3 FP3 and Maximo Asset Management 7.5 before 7.5.0.9 IF2, 7.5.1, and 7.6 before 7.6.0.3 FP3 for SmartCloud Control Desk allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
Affected products
12cpe:2.3:a:ibm:maximo_asset_management:7.5:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:ibm:maximo_asset_management:7.5:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:maximo_asset_management:7.6:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:maximo_asset_management_essentials:7.5:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:maximo_for_government:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:maximo_for_life_sciences:7.5:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:ibm:maximo_for_life_sciences:7.5:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:maximo_for_life_sciences:7.6:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:maximo_for_nuclear_power:7.5:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:maximo_for_oil_and_gas:7.5:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:maximo_for_transportation:7.5:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:maximo_for_utilities:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:smartcloud_control_desk:7.5:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:ibm:smartcloud_control_desk:7.5:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:smartcloud_control_desk:7.6:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www-01.ibm.com/support/docview.wssnvdVendor Advisory
News mentions
0No linked articles in our index yet.