CVE-2015-7396: IBM Maximo Asset Management

Medium severity, CVSS 5.4. EPSS: 0.8% chance of exploitation in the next 30 days.

The Scheduler in IBM Maximo Asset Management 7.5 before 7.5.0.8 IF6 and 7.6 before 7.6.0.1 FP1 and Maximo Asset Management 7.5 before 7.5.0.8 IF6, 7.5.1, and 7.6 before 7.6.0.1 FP1 for SmartCloud Control Desk allows remote authenticated users to bypass intended access restrictions, and obtain sensitive information or modify data, via unspecified vectors.

Affected products

  • IBM Maximo Asset Management: version 7.5 only; version 7.6 only
  • IBM Maximo Asset Management Essentials: version 7.5 only
  • IBM Maximo For Government: version 7.5 only
  • IBM Maximo For Life Sciences: version 7.5 only; version 7.6 only
  • IBM Maximo For Nuclear Power: version 7.5 only
  • IBM Maximo For Oil And Gas: version 7.5 only
  • IBM Maximo For Transportation: version 7.5 only
  • IBM Maximo For Utilities: version 7.5 only
  • IBM Smartcloud Control Desk: version 7.5 only; version 7.6 only

Published 2016-01-02. Last modified 2026-06-17.