VYPR

Maximo Application Suite

by IBM

CVEs (36)

  • CVE-2025-36386CriOct 28, 2025
    risk 0.64cvss 9.8epss 0.01

    IBM Maximo Application Suite 9.0.0 through 9.0.15 and 9.1.0 through 9.1.4 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the application.

  • CVE-2024-27266HigMar 14, 2024
    risk 0.53cvss 8.2epss 0.01

    IBM Maximo Application Suite 7.6.1.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 284566.

  • CVE-2025-2898HigMay 6, 2025
    risk 0.49cvss 7.5epss 0.00

    IBM Maximo Application Suite 9.0 could allow an attacker with some level of access to elevate their privileges due to a security configuration vulnerability in Role-Based Access Control (RBAC) configurations.

  • CVE-2024-22328HigApr 6, 2024
    risk 0.49cvss 7.5epss 0.01

    IBM Maximo Application Suite 8.10 and 8.11 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 279950.

  • CVE-2021-38924HigSep 14, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 210163.

  • CVE-2021-29854HigMay 3, 2022
    risk 0.47cvss 7.2epss 0.01

    IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. By sending a specially crafted HTTP request, a remote attacker could exploit this vulnerability to inject HTTP HOST header, which…

  • CVE-2023-43037MedApr 10, 2025
    risk 0.42cvss 6.5epss 0.00

    IBM Maximo Application Suite 8.11 and 9.0 could allow an authenticated user to perform unauthorized actions due to improper input validation.

  • CVE-2023-38723MedMar 13, 2024
    risk 0.42cvss 6.4epss 0.00

    IBM Maximo Application Suite 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. …

  • CVE-2022-35645MedMar 2, 2023
    risk 0.42cvss 6.4epss 0.00

    IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, 7.6.1.3 and IBM Maximo Application Suite 8.8 and 8.9 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially…

  • CVE-2024-35148MedJan 25, 2025
    risk 0.41cvss 6.3epss 0.00

    IBM Maximo Application Suite 8.10.10, 8.11.7, and 9.0 - Monitor Component is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.

  • CVE-2024-35145MedJan 25, 2025
    risk 0.40cvss 6.1epss 0.00

    IBM Maximo Application Suite 9.0.0 - Monitor Component is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials…

  • CVE-2022-43923MedFeb 24, 2023
    risk 0.40cvss 6.2epss 0.00

    IBM Maximo Application Suite 8.8.0 and 8.9.0 stores potentially sensitive information that could be read by a local user. IBM X-Force ID: 241584.

  • CVE-2022-41732MedNov 28, 2022
    risk 0.40cvss 6.2epss 0.00

    IBM Maximo Mobile 8.7 and 8.8 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 237407.

  • CVE-2024-38314MedOct 24, 2024
    risk 0.38cvss 5.9epss 0.00

    IBM Maximo Application Suite - Monitor Component 8.10, 8.11, and 9.0 could disclose information in the form of the hard-coded cryptographic key to an attacker that has compromised environment.

  • CVE-2024-37068MedSep 7, 2024
    risk 0.38cvss 5.9epss 0.00

    IBM Maximo Application Suite - Manage Component 8.10, 8.11, and 9.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information using man in the middle techniques.

  • CVE-2023-27861MedJun 5, 2023
    risk 0.38cvss 5.9epss 0.00

    IBM Maximo Application Suite - Manage Component 8.8.0 and 8.9.0 transmits sensitive information in cleartext that could be intercepted by an attacker using man in the middle techniques. IBM X-Force ID: 249208.

  • CVE-2025-1500MedApr 5, 2025
    risk 0.36cvss 5.5epss 0.00

    IBM Maximo Application Suite 9.0 could allow an authenticated user to upload a file with dangerous types that could be executed by another user if opened.

  • CVE-2022-35281MedJan 9, 2023
    risk 0.36cvss 5.5epss 0.01

    IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, 7.6.1.3 and the IBM Maximo Manage 8.3, 8.4 application in IBM Maximo Application Suite are vulnerable to CSV injection. IBM X-Force ID: 2306335.

  • CVE-2024-35146MedNov 6, 2024
    risk 0.35cvss 5.4epss 0.00

    IBM Maximo Application Suite - Monitor Component 8.10.11, 8.11.8, and 9.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading…

  • CVE-2023-32337MedJan 19, 2024
    risk 0.35cvss 5.4epss 0.00

    IBM Maximo Spatial Asset Management 8.10 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: …

Page 1 of 2