Show filters
27 Total Results
Displaying 1-10 of 27
Sort by:
Attacker Value
Unknown
CVE-2024-35150
Disclosure Date: January 25, 2025 (last updated January 26, 2025)
IBM Maximo Application Suite 8.10.12, 8.11.0, 9.0.1, and 9.1.0 - Monitor Component does not neutralize output that is written to logs, which could allow an attacker to inject false log entries.
0
Attacker Value
Unknown
CVE-2024-35148
Disclosure Date: January 25, 2025 (last updated January 26, 2025)
IBM Maximo Application Suite 8.10.10, 8.11.7, and 9.0 - Monitor Component is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
0
Attacker Value
Unknown
CVE-2024-35145
Disclosure Date: January 25, 2025 (last updated January 26, 2025)
IBM Maximo Application Suite 9.0.0 - Monitor Component is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
0
Attacker Value
Unknown
CVE-2024-35144
Disclosure Date: January 25, 2025 (last updated January 26, 2025)
IBM Maximo Application Suite 8.10, 8.11, and 9.0 - Monitor Component stores source code on the web server that could aid in further attacks against the system.
0
Attacker Value
Unknown
CVE-2024-35146
Disclosure Date: November 06, 2024 (last updated November 07, 2024)
IBM Maximo Application Suite - Monitor Component 8.10.11, 8.11.8, and 9.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
0
Attacker Value
Unknown
CVE-2024-38314
Disclosure Date: October 24, 2024 (last updated October 25, 2024)
IBM Maximo Application Suite - Monitor Component 8.10, 8.11, and 9.0 could disclose information in the form of the hard-coded cryptographic key to an attacker that has compromised environment.
0
Attacker Value
Unknown
CVE-2024-37068
Disclosure Date: September 07, 2024 (last updated September 21, 2024)
IBM Maximo Application Suite - Manage Component 8.10, 8.11, and 9.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information using man in the middle techniques.
0
Attacker Value
Unknown
CVE-2024-22333
Disclosure Date: June 13, 2024 (last updated August 08, 2024)
IBM Maximo Asset Management 7.6.1.3 and IBM Maximo Application Suite 8.10 and 8.11 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 279973.
0
Attacker Value
Unknown
CVE-2024-22328
Disclosure Date: April 06, 2024 (last updated January 15, 2025)
IBM Maximo Application Suite 8.10 and 8.11 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 279950.
0
Attacker Value
Unknown
CVE-2024-27266
Disclosure Date: March 14, 2024 (last updated April 01, 2024)
IBM Maximo Application Suite 7.6.1.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 284566.
0