IBM Vulnerabilities and Affected Products
Vulnerabilities associated with Maximo Application Suite.
Products
Clear product- Db2 for Linux, UNIX and Windows168 vulnerabilities
- i162 vulnerabilities
- WebSphere Application Server152 vulnerabilities
- InfoSphere Information Server146 vulnerabilities
- Sterling B2B Integrator132 vulnerabilities
- Rational Quality Manager126 vulnerabilities
- Rational Collaborative Lifecycle Management114 vulnerabilities
- Security Guardium106 vulnerabilities
- QRadar SIEM100 vulnerabilities
- Cognos Analytics98 vulnerabilities
- Rational DOORS Next Generation91 vulnerabilities
- MQ83 vulnerabilities
- Maximo Asset Management81 vulnerabilities
- API Connect78 vulnerabilities
- Rational Engineering Lifecycle Manager76 vulnerabilities
- Rational Team Concert72 vulnerabilities
- AIX69 vulnerabilities
- Langflow OSS68 vulnerabilities
- Sterling File Gateway64 vulnerabilities
- Security Key Lifecycle Manager57 vulnerabilities
- Security Verify Access57 vulnerabilities
- Cloud Pak for Security55 vulnerabilities
- Cognos Controller52 vulnerabilities
- Engineering Lifecycle Optimization52 vulnerabilities
- Spectrum Protect Plus49 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-15656MEDIUM | IBM MAS uses axios-1.15.2, protobufjs-8.0.1 and undici-7.26 which is vulnerable to multiple CVEs, and contains vulnerabilities related to missing Secure attribute on mas-redirect-uri cookie and weak HMAC Session SecretIBM Maximo Application Suite 9.2, 9.1, and 9.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. CWE-614Aug 5, 2026 | CVSS4.3v3.1 | EPSS0.187% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-18531MEDIUM | IBM MAS uses axios-1.15.2, protobufjs-8.0.1 and undici-7.26 which is vulnerable to multiple CVEs, and contains vulnerabilities related to missing Secure attribute on mas-redirect-uri cookie and weak HMAC Session SecretIBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with session data due to the use of a weak HMAC session signing secret. CWE-330Aug 5, 2026 | CVSS5.3v3.1 | EPSS0.378% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-4820MEDIUM | IBM Maximo Application Suite was vulnerable to because Cookie ltpatoken2_<workspace_name> was not set with secure flagIBM Maximo Application Suite 9.1, 9.0, 8.11, and 8.10 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. | CVSS4.3v3.1 | EPSS0.118% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-2898HIGH | IBM Maximo Application Suite privilege escalationIBM Maximo Application Suite 9.0 could allow an attacker with some level of access to elevate their privileges due to a security configuration vulnerability in Role-Based Access Control (RBAC) configurations. CWE-266May 6, 2025 | CVSS7.5v3.1 | EPSS0.328% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-43037MEDIUM | IBM Maximo Application Suite improper access controlIBM Maximo Application Suite 8.11 and 9.0 could allow an authenticated user to perform unauthorized actions due to improper input validation. CWE-20Apr 10, 2025 | CVSS6.5v3.1 | EPSS0.311% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-1500MEDIUM | IBM Maximo Application Suite file uploadIBM Maximo Application Suite 9.0 could allow an authenticated user to upload a file with dangerous types that could be executed by another user if opened. CWE-434Apr 5, 2025 | CVSS5.5v3.1 | EPSS0.267% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-35150MEDIUM | IBM Maximo Application Suite log manipulationIBM Maximo Application Suite 8.10.12, 8.11.0, 9.0.1, and 9.1.0 - Monitor Component does not neutralize output that is written to logs, which could allow an attacker to inject false log entries. CWE-117Jan 25, 2025 | CVSS5.3v3.1 | EPSS0.278% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-35148MEDIUM | IBM Maximo Application Suite SQL injectionIBM Maximo Application Suite 8.10.10, 8.11.7, and 9.0 - Monitor Component is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. CWE-89Jan 25, 2025 | CVSS6.3v3.1 | EPSS0.352% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-35144MEDIUM | IBM Maximo Application Suite information disclosureIBM Maximo Application Suite 8.10, 8.11, and 9.0 - Monitor Component stores source code on the web server that could aid in further attacks against the system. CWE-540Jan 25, 2025 | CVSS5.3v3.1 | EPSS0.3% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-35145MEDIUM | IBM Maximo Application Suite cross-site scriptingIBM Maximo Application Suite 9.0.0 - Monitor Component is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. CWE-79Jan 25, 2025 | CVSS6.1v3.1 | EPSS0.253% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-35146MEDIUM | IBM Maximo Application Suite cross-site scriptingIBM Maximo Application Suite - Monitor Component 8.10.11, 8.11.8, and 9.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. CWE-79Nov 6, 2024 | CVSS5.4v3.1 | EPSS0.253% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-37068MEDIUM | IBM Maximo Application Suite information disclosureIBM Maximo Application Suite - Manage Component 8.10, 8.11, and 9.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information using man in the middle techniques. CWE-327Sep 7, 2024 | CVSS5.9v3.1 | EPSS0.247% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
IBM Maximo Application Suite information disclosureIBM Maximo Asset Management 7.6.1.3 and IBM Maximo Application Suite 8.10 and 8.11 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 279973. | CVSS3.3v3.1 | EPSS0.18% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2024-22328HIGH | IBM Maximo Application Suite information disclosureIBM Maximo Application Suite 8.10 and 8.11 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 279950. CWE-22Apr 6, 2024 | CVSS7.5v3.1 | EPSS0.843% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
IBM Maximo Application Suite information disclosureIBM Maximo Application Suite 8.10, 8.11 and IBM Maximo Asset Management 7.6.1.3 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 255075. CWE-598Mar 13, 2024 | CVSS3.7v3.1 | EPSS0.503% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2023-32332MEDIUM | IBM Maximo Application Suite and IBM Maximo Asset Management HTML injectionIBM Maximo Application Suite 8.9, 8.10 and IBM Maximo Asset Management 7.6.1.2, 7.6.1.3 are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 255072. CWE-79Sep 8, 2023 | CVSS5.4v3.1 | EPSS0.493% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
IBM Maximo Asset Management information disclosureIBM Maximo Asset Management 7.6.1.2, 7.6.1.3 and IBM Maximo Application Suite 8.8.0 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 255074. Jun 5, 2023 | CVSS3.7v3.1 | EPSS0.642% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2023-27861MEDIUM | IBM Maximo Application Suite information disclosureIBM Maximo Application Suite - Manage Component 8.8.0 and 8.9.0 transmits sensitive information in cleartext that could be intercepted by an attacker using man in the middle techniques. IBM X-Force ID: 249208. CWE-319Jun 5, 2023 | CVSS5.9v3.1 | EPSS0.338% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-35645MEDIUM | IBM Maximo Asset Management cross-site scriptingIBM Maximo Asset Management 7.6.1.1, 7.6.1.2, 7.6.1.3 and IBM Maximo Application Suite 8.8 and 8.9 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 230958. CWE-79Mar 2, 2023 | CVSS6.4v3.1 | EPSS0.493% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-43923MEDIUM | IBM Maximo Application Suite 8.8.0 and 8.9.0 stores potentially sensitive information that could be read by a local user. IBM X-Force ID: 241584. CWE-532Feb 24, 2023 | CVSS6.2v3.1 | EPSS0.189% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |