VYPR

Maximo Application Suite

by IBM

CVEs (36)

  • CVE-2023-32332MedSep 8, 2023
    risk 0.35cvss 5.4epss 0.00

    IBM Maximo Application Suite 8.9, 8.10 and IBM Maximo Asset Management 7.6.1.2, 7.6.1.3 are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the…

  • CVE-2022-46774MedMar 15, 2023
    risk 0.35cvss 5.4epss 0.00

    IBM Manage Application 8.8.0 and 8.9.0 in the IBM Maximo Application Suite is vulnerable to incorrect default permissions which could give access to a user to actions that they should not have access to. IBM X-Force ID: 242953.

  • CVE-2021-29743MedAug 30, 2021
    risk 0.35cvss 5.4epss 0.01

    IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted…

  • CVE-2021-29744MedAug 27, 2021
    risk 0.35cvss 5.4epss 0.01

    IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.…

  • CVE-2026-18531MedAug 5, 2026
    risk 0.34cvss 5.3epss 0.00

    IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with session data due to the use of a weak HMAC session signing secret.

  • CVE-2024-35150MedJan 25, 2025
    risk 0.34cvss 5.3epss 0.00

    IBM Maximo Application Suite 8.10.12, 8.11.0, 9.0.1, and 9.1.0 - Monitor Component does not neutralize output that is written to logs, which could allow an attacker to inject false log entries.

  • CVE-2024-35144MedJan 25, 2025
    risk 0.34cvss 5.3epss 0.00

    IBM Maximo Application Suite 8.10, 8.11, and 9.0 - Monitor Component stores source code on the web server that could aid in further attacks against the system.

  • CVE-2022-41734MedFeb 17, 2023
    risk 0.34cvss 5.3epss 0.01

    IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 237587.

  • CVE-2023-43043MedMar 13, 2024
    risk 0.33cvss 5.1epss 0.00

    IBM Maximo Application Suite - Maximo Mobile for EAM 8.10 and 8.11 could disclose sensitive information to a local user. IBM X-Force ID: 266875.

  • CVE-2026-15656MedAug 5, 2026
    risk 0.28cvss 4.3epss 0.00

    IBM Maximo Application Suite 9.2, 9.1, and 9.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be…

  • CVE-2026-4820MedApr 1, 2026
    risk 0.28cvss 4.3epss 0.00

    IBM Maximo Application Suite 9.1, 9.0, 8.11, and 8.10 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie…

  • CVE-2023-47718MedJan 19, 2024
    risk 0.28cvss 4.3epss 0.00

    IBM Maximo Asset Management 7.6.1.3 and Manage Component 8.10 through 8.11 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 271843.

  • CVE-2025-14684MedMar 25, 2026
    risk 0.26cvss 4.0epss 0.00

    IBM Maximo Application Suite - Monitor Component 9.1, 9.0, 8.11, and 8.10 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.

  • CVE-2023-32335LowMar 13, 2024
    risk 0.24cvss 3.7epss 0.01

    IBM Maximo Application Suite 8.10, 8.11 and IBM Maximo Asset Management 7.6.1.3 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM…

  • CVE-2023-32334LowJun 5, 2023
    risk 0.24cvss 3.7epss 0.01

    IBM Maximo Asset Management 7.6.1.2, 7.6.1.3 and IBM Maximo Application Suite 8.8.0 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM…

  • CVE-2024-22333LowJun 13, 2024
    risk 0.21cvss 3.3epss 0.00

    IBM Maximo Asset Management 7.6.1.3 and IBM Maximo Application Suite 8.10 and 8.11 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 279973.

Page 2 of 2