VYPR

Maximo Application Suite - Monitor Component

by IBM

CVEs (4)

  • CVE-2024-35148MedJan 25, 2025
    risk 0.41cvss 6.3epss 0.00

    IBM Maximo Application Suite 8.10.10, 8.11.7, and 9.0 - Monitor Component is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.

  • CVE-2024-38314MedOct 24, 2024
    risk 0.38cvss 5.9epss 0.00

    IBM Maximo Application Suite - Monitor Component 8.10, 8.11, and 9.0 could disclose information in the form of the hard-coded cryptographic key to an attacker that has compromised environment.

  • CVE-2024-35146MedNov 6, 2024
    risk 0.35cvss 5.4epss 0.00

    IBM Maximo Application Suite - Monitor Component 8.10.11, 8.11.8, and 9.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading…

  • CVE-2024-35144MedJan 25, 2025
    risk 0.34cvss 5.3epss 0.00

    IBM Maximo Application Suite 8.10, 8.11, and 9.0 - Monitor Component stores source code on the web server that could aid in further attacks against the system.