PT-2025-2432 · Ibm · Ibm Maximo Application Suite

Published

2025-01-25

·

Updated

2025-07-08

·

CVE-2024-35144

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: IBM Maximo Application Suite versions 8.10 through 9.0
Description: The issue is related to the Monitor Component of the IBM Maximo Application Suite, which stores source code on the web server. This could aid in further attacks against the system. The vulnerability is associated with insufficient protection of service data in the source code, allowing a remote attacker to gain unauthorized access to protected information.
Recommendations: For versions 8.10 through 9.0, update to a version that does not store source code on the web server to prevent further attacks. As a temporary workaround, consider restricting access to the Monitor Component until a patch is available. Avoid using the Monitor Component in sensitive environments until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2025-01190
CVE-2024-35144

Affected Products

Ibm Maximo Application Suite