Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Maximo Application Suite — Vulnerabilities & Security Advisories 17

All 17 CVE vulnerabilities found in Maximo Application Suite, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities for IBM Maximo Application Suite, a web-based asset management platform, specifically covering weaknesses categorized under the "CWE-79: Cross-site Scripting" tag. It collects documented security flaws, including cross-site scripting, denial of service, and privilege escalation issues, spanning advisories released between 2010 and 2024. Readers can use this resource to track IBM’s security advisories for this product, understand the specific mechanics of common weakness classes, and review the full vulnerability history of the application suite. The data is presented in a structured format, allowing users to filter by year, severity, or weakness type to analyze trends in the product’s security posture over time.

Vendor: IBM

CVE ID Title CVSS Severity Published
CVE-2026-15656 IBM MAS uses axios-1.15.2, protobufjs-8.0.1 and undici-7.26 which is vulnerable to multiple CVEs, and contains vulnerabilities related to missing Secure attribute on mas-redirect-uri cookie and weak HMAC Session Secret CWE-614 4.3 Medium 2026-08-05
CVE-2026-18531 IBM MAS uses axios-1.15.2, protobufjs-8.0.1 and undici-7.26 which is vulnerable to multiple CVEs, and contains vulnerabilities related to missing Secure attribute on mas-redirect-uri cookie and weak HMAC Session Secret CWE-330 5.3 Medium 2026-08-05
CVE-2026-4820 IBM Maximo Application Suite was vulnerable to because Cookie ltpatoken2_<workspace_name> was not set with secure flag CWE-614 4.3 Medium 2026-04-01
CVE-2025-2898 IBM Maximo Application Suite privilege escalation CWE-266 7.5 High 2025-05-06
CVE-2023-43037 IBM Maximo Application Suite improper access control CWE-20 6.5 Medium 2025-04-10
CVE-2025-1500 IBM Maximo Application Suite file upload CWE-434 5.5 Medium 2025-04-05
CVE-2024-35150 IBM Maximo Application Suite log manipulation CWE-117 5.3 Medium 2025-01-25
CVE-2024-35148 IBM Maximo Application Suite SQL injection CWE-89 6.3 Medium 2025-01-25
CVE-2024-35144 IBM Maximo Application Suite information disclosure CWE-540 5.3 Medium 2025-01-25
CVE-2024-35145 IBM Maximo Application Suite cross-site scripting CWE-79 6.1 Medium 2025-01-25
CVE-2024-35146 IBM Maximo Application Suite cross-site scripting CWE-79 5.4 Medium 2024-11-06
CVE-2024-37068 IBM Maximo Application Suite information disclosure CWE-327 5.9 Medium 2024-09-07
CVE-2024-22333 IBM Maximo Application Suite information disclosure CWE-525 3.3 Low 2024-06-13
CVE-2024-22328 IBM Maximo Application Suite information disclosure CWE-22 7.5 High 2024-04-06
CVE-2023-32335 IBM Maximo Application Suite information disclosure CWE-598 3.7 Low 2024-03-13
CVE-2023-27861 IBM Maximo Application Suite information disclosure CWE-319 5.9 Medium 2023-06-05
CVE-2022-43923 IBM Maximo Application Suite 日志信息泄露漏洞 CWE-532 6.2 Medium 2023-02-24

All 17 known CVE vulnerabilities affecting Maximo Application Suite with full Chinese analysis, references, and POCs where available.