cbcvebase.

Ibm Maximo Application Suite vulnerabilities

32 known vulnerabilities affecting ibm/maximo_application_suite.

Total CVEs
32
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH12MEDIUM17LOW2

Vulnerabilities

Page 2 of 2
CVE-2024-35150P4MEDIUMCVSS 5.3≥ 8.10.12, < 8.10.15≥ 8.11, < 8.11.13+3 more2025-01-25
CVE-2024-35150 [MEDIUM] CWE-117 CVE-2024-35150: IBM Maximo Application Suite 8.10.12, 8.11.0, 9.0.1, and 9.1.0 - Monitor Component does not neutrali IBM Maximo Application Suite 8.10.12, 8.11.0, 9.0.1, and 9.1.0 - Monitor Component does not neutralize output that is written to logs, which could allow an attacker to inject false log entries.
nvd
CVE-2024-35146P4MEDIUMCVSS 5.4v8.10.11v8.11.8+2 more2024-11-06
CVE-2024-35146 [MEDIUM] CWE-79 CVE-2024-35146: IBM Maximo Application Suite - Monitor Component 8.10.11, 8.11.8, and 9.0.0 is vulnerable to cross-s IBM Maximo Application Suite - Monitor Component 8.10.11, 8.11.8, and 9.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2023-32332P4MEDIUMCVSS 5.4v8.9v8.10+1 more2023-09-08
CVE-2023-32332 [MEDIUM] CWE-79 CVE-2023-32332: IBM Maximo Application Suite 8.9, 8.10 and IBM Maximo Asset Management 7.6.1.2, 7.6.1.3 are vulnerab IBM Maximo Application Suite 8.9, 8.10 and IBM Maximo Asset Management 7.6.1.2, 7.6.1.3 are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 255072.
nvd
CVE-2023-32334P4MEDIUMCVSS 5.3v8.8.02023-06-05
CVE-2023-32334 [MEDIUM] CVE-2023-32334: IBM Maximo Asset Management 7.6.1.2, 7.6.1.3 and IBM Maximo Application Suite 8.8.0 stores sensitive IBM Maximo Asset Management 7.6.1.2, 7.6.1.3 and IBM Maximo Application Suite 8.8.0 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 255074.
nvd
CVE-2021-29743P4MEDIUMCVSS 5.4≥ 8.0, ≤ 8.42021-08-30
CVE-2021-29743 [MEDIUM] CWE-79 CVE-2021-29743: IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to stored cross-site scripting. This vulne IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 201693.
nvd
CVE-2021-29744P4MEDIUMCVSS 5.4v8.42021-08-27
CVE-2021-29744 [MEDIUM] CWE-79 CVE-2021-29744: IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site scripting. This vulnerabilit IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 201694.
nvd
CVE-2022-35645P4MEDIUMCVSS 5.4v8.8.0v8.9.0+1 more2023-03-02
CVE-2022-35645 [MEDIUM] CWE-79 CVE-2022-35645: IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, 7.6.1.3 and IBM Maximo Application Suite 8.8 and 8.9 i IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, 7.6.1.3 and IBM Maximo Application Suite 8.8 and 8.9 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force I
nvd
CVE-2022-41732P4MEDIUMCVSS 5.5v8.7v8.82022-11-28
CVE-2022-41732 [MEDIUM] CWE-256 CVE-2022-41732: IBM Maximo Mobile 8.7 and 8.8 stores user credentials in plain clear text which can be read by a lo IBM Maximo Mobile 8.7 and 8.8 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 237407.
nvd
CVE-2022-43923P4MEDIUMCVSS 5.5v8.8.0v8.9.0+1 more2023-02-24
CVE-2022-43923 [MEDIUM] CWE-532 CVE-2022-43923: IBM Maximo Application Suite 8.8.0 and 8.9.0 stores potentially sensitive information that could be IBM Maximo Application Suite 8.8.0 and 8.9.0 stores potentially sensitive information that could be read by a local user. IBM X-Force ID: 241584.
nvd
CVE-2026-4820P4MEDIUMCVSS 4.3≥ 8.10, < 8.10.33≥ 8.11, < 8.11.30+6 more2026-04-01
CVE-2026-4820 [MEDIUM] CWE-614 CVE-2026-4820: IBM Maximo Application Suite 9.1, 9.0, 8.11, and 8.10 does not set the secure attribute on authoriza IBM Maximo Application Suite 9.1, 9.0, 8.11, and 8.10 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the coo
nvd
CVE-2025-14684P4LOWCVSS 3.3≥ 8.10, < 8.10.26≥ 8.11, < 8.11.24+2 more2026-03-25
CVE-2025-14684 [LOW] CWE-117 CVE-2025-14684: IBM Maximo Application Suite - Monitor Component 9.1, 9.0, 8.11, and 8.10 could allow an unauthorize IBM Maximo Application Suite - Monitor Component 9.1, 9.0, 8.11, and 8.10 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.
nvd
CVE-2024-22333P4LOWCVSS 3.3v8.10v8.11+1 more2024-06-13
CVE-2024-22333 [LOW] CWE-525 CVE-2024-22333: IBM Maximo Asset Management 7.6.1.3 and IBM Maximo Application Suite 8.10 and 8.11 allows web pages IBM Maximo Asset Management 7.6.1.3 and IBM Maximo Application Suite 8.10 and 8.11 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 279973.
nvd