PT-2025-2432 · Ibm · Ibm Maximo Application Suite
Published
2025-01-25
·
Updated
2025-07-08
·
CVE-2024-35144
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
IBM Maximo Application Suite versions 8.10 through 9.0
Description:
The issue is related to the Monitor Component of the IBM Maximo Application Suite, which stores source code on the web server. This could aid in further attacks against the system. The vulnerability is associated with insufficient protection of service data in the source code, allowing a remote attacker to gain unauthorized access to protected information.
Recommendations:
For versions 8.10 through 9.0, update to a version that does not store source code on the web server to prevent further attacks.
As a temporary workaround, consider restricting access to the Monitor Component until a patch is available.
Avoid using the Monitor Component in sensitive environments until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Maximo Application Suite