VendorsIBMmaximo_application_suiteall versions
Vulnerabilities

IBM Maximo Application Suite

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

35CVEs
CVE-2025-36386
There is a vulnerability in the IBM Maximo Manage application in IBM Maximo Application Suite for Cognos Analytics
Published 2025-10-28 · Analyzed
9.8EPSS 0.005
CVE-2022-35281
IBM Maximo Application Suite command injection
Published 2023-01-06 · Modified
8.8EPSS 0.005
CVE-2024-35148
IBM Maximo Application Suite SQL injection
Published 2025-01-25 · Analyzed
8.8EPSS 0.004
CVE-2025-2898
IBM Maximo Application Suite privilege escalation
Published 2025-05-06 · Analyzed
8.8EPSS 0.003
CVE-2023-47718
IBM Maximo Asset Management cross-site request forgery
Published 2024-01-19 · Modified
8.8EPSS 0.003
CVE-2024-27266
IBM Maximo Application Suite XML external entity injection
Published 2024-03-14 · Modified
8.2EPSS 0.008
CVE-2025-1500
IBM Maximo Application Suite file upload
Published 2025-04-05 · Analyzed
8.0EPSS 0.003
CVE-2021-38924
IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 210163.
Published 2022-09-14 · Modified
7.5EPSS 0.010
CVE-2024-22328
IBM Maximo Application Suite information disclosure
Published 2024-04-06 · Analyzed
7.5EPSS 0.008
CVE-2022-41734
IBM Maximo Asset Management information disclosure
Published 2023-02-17 · Modified
7.5EPSS 0.005
CVE-2023-32335
IBM Maximo Application Suite information disclosure
Published 2024-03-13 · Analyzed
7.5EPSS 0.005
CVE-2024-37068
IBM Maximo Application Suite information disclosure
Published 2024-09-07 · Modified
7.5EPSS 0.002
CVE-2021-29854
IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. By sending a specially crafted HTTP request, a remote attacker could exploit this vulnerability to inject HTTP HOST header, which will allow the attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 205680.
Published 2022-05-03 · Modified
7.2EPSS 0.011
CVE-2022-46774
IBM Manage Application security bypass
Published 2023-03-15 · Modified
6.5EPSS 0.003
CVE-2023-43037
IBM Maximo Application Suite improper access control
Published 2025-04-10 · Analyzed
6.5EPSS 0.003
CVE-2021-29743
IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 201693.
Published 2021-08-30 · Modified
6.4EPSS 0.005
CVE-2022-35645
IBM Maximo Asset Management cross-site scripting
Published 2023-03-02 · Modified
6.4EPSS 0.005
CVE-2023-38723
Maximo Asset Management cross-site scripting
Published 2024-03-13 · Analyzed
6.4EPSS 0.003
CVE-2022-43923
IBM Maximo Application Suite 8.8.0 and 8.9.0 stores potentially sensitive information that could be read by a local user. IBM X-Force ID: 241584.
Published 2023-02-24 · Modified
6.2EPSS 0.002
CVE-2022-41732
IBM Maximo information disclosure
Published 2022-11-28 · Modified
6.2EPSS 0.002
CVE-2024-35145
IBM Maximo Application Suite cross-site scripting
Published 2025-01-25 · Analyzed
6.1EPSS 0.003
CVE-2023-27861
IBM Maximo Application Suite information disclosure
Published 2023-06-05 · Modified
5.9EPSS 0.003
CVE-2024-38314
IBM Maximo Application Suite - Monitor Component information disclosure
Published 2024-10-24 · Analyzed
5.9EPSS 0.003
CVE-2023-32332
IBM Maximo Application Suite and IBM Maximo Asset Management HTML injection
Published 2023-09-08 · Modified
5.4EPSS 0.006
CVE-2021-29744
IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 201694.
Published 2021-08-27 · Modified
5.4EPSS 0.005
CVE-2023-32337
IBM Maximo Spatial Asset Management server-side request forgery
Published 2024-01-19 · Modified
5.4EPSS 0.003
CVE-2024-35146
IBM Maximo Application Suite cross-site scripting
Published 2024-11-06 · Analyzed
5.4EPSS 0.003
CVE-2023-32334
IBM Maximo Asset Management information disclosure
Published 2023-06-05 · Modified
5.3EPSS 0.006
CVE-2024-35144
IBM Maximo Application Suite information disclosure
Published 2025-01-25 · Analyzed
5.3EPSS 0.003
CVE-2024-35150
IBM Maximo Application Suite log manipulation
Published 2025-01-25 · Analyzed
5.3EPSS 0.003
CVE-2026-18531
IBM MAS uses axios-1.15.2, protobufjs-8.0.1 and undici-7.26 which is vulnerable to multiple CVEs, and contains vulnerabilities related to missing Secure attribute on mas-redirect-uri cookie and weak HMAC Session Secret
Published 2026-08-05 · Analyzed
5.3EPSS 0.002
CVE-2026-4820
IBM Maximo Application Suite was vulnerable to because Cookie ltpatoken2_<workspace_name> was not set with secure flag
Published 2026-04-01 · Analyzed
4.3EPSS 0.001
CVE-2026-15656
IBM MAS uses axios-1.15.2, protobufjs-8.0.1 and undici-7.26 which is vulnerable to multiple CVEs, and contains vulnerabilities related to missing Secure attribute on mas-redirect-uri cookie and weak HMAC Session Secret
Published 2026-08-05 · Analyzed
4.3EPSS 0.001
CVE-2025-14684
IBM Maximo Application Suite - Monitor Component uses Log Forging which is vulnerable to .
Published 2026-03-25 · Analyzed
4.0EPSS 0.001
CVE-2024-22333
IBM Maximo Application Suite information disclosure
Published 2024-06-13 · Modified
3.3EPSS 0.002