Maximo application suite
This hub aggregates every CVE we track for Maximo application suite, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
34
CVEs tracked
1
Critical
5
High
0
In CISA KEV
Severity distribution
MEDIUM25HIGH5LOW3CRITICAL1
Monthly trend
1
1
1
0
4
0
0
2
1
0
0
0
0
1
0
0
0
0
1
1
0
0
0
2
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Maximo application suite.
- CVE-2026-15656IBM MAS uses axios-1.15.2, protobufjs-8.0.1 and undici-7.26 which is vulnerable to multiple CVEs, and contains vulnerabilities related to missing Secure attribute on mas-redirect-uri cookie and weak HMAC Session Secret4.3
- CVE-2026-18531IBM MAS uses axios-1.15.2, protobufjs-8.0.1 and undici-7.26 which is vulnerable to multiple CVEs, and contains vulnerabilities related to missing Secure attribute on mas-redirect-uri cookie and weak HMAC Session Secret5.3
- CVE-2026-4820IBM Maximo Application Suite was vulnerable to because Cookie ltpatoken2_<workspace_name> was not set with secure flag4.3
- CVE-2025-14684IBM Maximo Application Suite - Monitor Component uses Log Forging which is vulnerable to .4.0
- CVE-2025-36386There is a vulnerability in the IBM Maximo Manage application in IBM Maximo Application Suite for Cognos Analytics9.8
- CVE-2025-2898IBM Maximo Application Suite privilege escalation7.5
- CVE-2023-43037IBM Maximo Application Suite improper access control6.5
- CVE-2025-1500IBM Maximo Application Suite file upload5.5
- CVE-2024-35150IBM Maximo Application Suite log manipulation5.3
- CVE-2024-35148IBM Maximo Application Suite SQL injection6.3
- CVE-2024-35144IBM Maximo Application Suite information disclosure5.3
- CVE-2024-35145IBM Maximo Application Suite cross-site scripting6.1
- CVE-2024-35146IBM Maximo Application Suite cross-site scripting5.4
- CVE-2024-38314IBM Maximo Application Suite - Monitor Component information disclosure5.9
- CVE-2024-37068IBM Maximo Application Suite information disclosure5.9
Product normalization is registry-driven with AI assist and human review. How it works