IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow an authenticated user to view incorrect item sets that they should not have access to view.
https://exchange.xforce.ibmcloud.com/vulnerabilities/119039
https://euvd.enisa.europa.eu/vulnerability/EUVD-2016-9812