Skip to main content

Vendor/product archive

ibm / maximo_application_suite CVEs

Beta · best-effort

33 CVEs tagged to ibm / maximo_application_suite1 Critical, 5 High, 24 Medium, 3 Low, 0 Unrated.

CVE-2026-4820

Published Apr 1, 2026

IBM Maximo Application Suite 9.1, 9.0, 8.11, and 8.10 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-14684

Published Mar 25, 2026

IBM Maximo Application Suite - Monitor Component 9.1, 9.0, 8.11, and 8.10 could allow an unauthorized user to inject data into log messages due to improper neutralization of speci…

CVSS 4.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-36386

Published Oct 28, 2025

IBM Maximo Application Suite 9.0.0 through 9.0.15 and 9.1.0 through 9.1.4 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the app…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-2898

Published May 6, 2025

IBM Maximo Application Suite 9.0 could allow an attacker with some level of access to elevate their privileges due to a security configuration vulnerability in Role-Based Access C…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-43037

Published Apr 10, 2025

IBM Maximo Application Suite 8.11 and 9.0 could allow an authenticated user to perform unauthorized actions due to improper input validation.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-1500

Published Apr 5, 2025

IBM Maximo Application Suite 9.0 could allow an authenticated user to upload a file with dangerous types that could be executed by another user if opened.

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-35150

Published Jan 25, 2025

IBM Maximo Application Suite 8.10.12, 8.11.0, 9.0.1, and 9.1.0 - Monitor Component does not neutralize output that is written to logs, which could allow an attacker to inject fals…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-35148

Published Jan 25, 2025

IBM Maximo Application Suite 8.10.10, 8.11.7, and 9.0 - Monitor Component is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which coul…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-35145

Published Jan 25, 2025

IBM Maximo Application Suite 9.0.0 - Monitor Component is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript c…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-35144

Published Jan 25, 2025

IBM Maximo Application Suite 8.10, 8.11, and 9.0 - Monitor Component stores source code on the web server that could aid in further attacks against the system.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-35146

Published Nov 6, 2024

IBM Maximo Application Suite - Monitor Component 8.10.11, 8.11.8, and 9.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed a…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-38314

Published Oct 24, 2024

IBM Maximo Application Suite - Monitor Component 8.10, 8.11, and 9.0 could disclose information in the form of the hard-coded cryptographic key to an attacker that has compromised…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37068

Published Sep 7, 2024

IBM Maximo Application Suite - Manage Component 8.10, 8.11, and 9.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive inf…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-22328

Published Apr 6, 2024

IBM Maximo Application Suite 8.10 and 8.11 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-27266

Published Mar 14, 2024

IBM Maximo Application Suite 7.6.1.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-38723

Published Mar 13, 2024

IBM Maximo Application Suite 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering t…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-27861

Published Jun 5, 2023

IBM Maximo Application Suite - Manage Component 8.8.0 and 8.9.0 transmits sensitive information in cleartext that could be intercepted by an attacker using man in the middle techn…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 33 CVEsPage 1 of 2