CVE-2014-0849: IBM Maximo Asset Management

Medium severity, CVSS 6.0. EPSS: 1.1% chance of exploitation in the next 30 days.

IBM Maximo Asset Management 7.x before 7.5.0.3 IFIX027 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allow remote authenticated users to gain privileges by leveraging membership in two security groups.

Affected products

  • IBM Maximo Asset Management: version 7.1 only; version 7.1.1 only; version 7.1.1.1 only; version 7.1.1.2 only; version 7.1.1.5 only; version 7.1.1.6 only; …
  • IBM Smartcloud Control Desk: version 7.0 only; version 7.5 only; version 7.5.0.0 only; version 7.5.0.1 only; version 7.5.0.2 only; version 7.5.0.3 only; …

Published 2014-05-26. Last modified 2026-06-17.