📦 Maximo Application Suite

by Ibm

🔍 What is Maximo Application Suite?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-36386

CRITICAL CVSS 9.8 Oct 28, 2025

CVE-2025-36386 is an authentication bypass vulnerability in IBM Maximo Application Suite that allows remote attackers to gain unauthorized access without valid credentials. This affects IBM Maximo App...

CVE-2025-2898

HIGH CVSS 7.5 May 6, 2025

This vulnerability in IBM Maximo Application Suite 9.0 allows authenticated attackers to escalate their privileges due to misconfigured Role-Based Access Control (RBAC) settings. Attackers with some i...

CVE-2024-22328

HIGH CVSS 7.5 Apr 6, 2024

This vulnerability allows remote attackers to perform directory traversal attacks on IBM Maximo Application Suite systems. By sending specially crafted URL requests containing 'dot dot' sequences (/.....

CVE-2024-27266

HIGH CVSS 8.2 Mar 14, 2024

IBM Maximo Application Suite 7.6.1.3 contains an XML External Entity (XXE) vulnerability that allows attackers to read sensitive files from the server or cause denial of service through resource exhau...

CVE-2023-43037

MEDIUM CVSS 6.5 Apr 10, 2025

This vulnerability in IBM Maximo Application Suite allows authenticated users to perform unauthorized actions due to improper input validation. It affects Maximo Application Suite versions 8.11 and 9....

CVE-2025-1500

MEDIUM CVSS 5.5 Apr 5, 2025

This vulnerability in IBM Maximo Application Suite 9.0 allows authenticated users to upload files with dangerous extensions that could be executed by other users. Attackers could potentially execute m...

CVE-2024-35148

MEDIUM CVSS 6.3 Jan 25, 2025

This SQL injection vulnerability in IBM Maximo Application Suite's Monitor Component allows remote attackers to execute arbitrary SQL commands. Successful exploitation could enable attackers to read, ...

CVE-2024-35144

MEDIUM CVSS 5.3 Jan 25, 2025

IBM Maximo Application Suite's Monitor Component stores source code files on the web server that could be accessed by attackers. This information disclosure vulnerability could help attackers understa...

CVE-2024-38314

MEDIUM CVSS 5.9 Oct 24, 2024

IBM Maximo Application Suite Monitor Component versions 8.10, 8.11, and 9.0 contain a hard-coded cryptographic key vulnerability. This allows attackers who have already compromised the environment to ...