Security Bulletin: XSS, Gain Privileges, Improper Access Control vulnerabilities in Maximo Asset Mgmt, Tivoli Asset Mgmt for IT, Tivoli Service Request Mgr, Change and Configuration Mgmt Database, and SmartCloud Control Desk. See Details for CVE IDs.
VULNERABILITY DETAILS:
Customers who have Maximo Asset Management, Maximo Asset Management Essentials, Tivoli Asset Management for IT, Tivoli Service Request Manager, Change and Configuration Management Database, and SmartCloud Control Desk are potentially impacted by these vulnerabilities, which can cause issues related to Cross-Site Scripting (XSS), which can be used to bypass access controls, gaining elevated privileges, and improper access control. View IBM Security Vulnerabilities Address in Asset and Service Mgmt for more details…