CVE-2024-37068

Severity
7.5HIGH
EPSS
0.1%
top 78.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 7

Description

IBM Maximo Application Suite - Manage Component 8.10, 8.11, and 9.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information using man in the middle techniques.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages2 packages

CVEListV5ibm/maximo_application_suite8.10, 8.11, 9.0
NVDibm/maximo_application_suite8.10, 8.11, 9.0+2

🔴Vulnerability Details

2
CVEList
IBM Maximo Application Suite information disclosure2024-09-07
GHSA
GHSA-9v5v-xqrh-46ph: IBM Maximo Application Suite - Manage Component 82024-09-07
CVE-2024-37068 (HIGH CVSS 7.5) | IBM Maximo Application Suite - Mana | cvebase.io