Maximo Application Suite

Vendor:

First CVE: Aug 27, 2021 · Active for 4 years

33
Total CVEs
More Total CVEs than 96% of tracked products
5.5
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 29% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Maximo Application Suite over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 27, 2021
4 years ago
Most Recent CVE
Apr 1, 2026
114 days ago

CVE Severity & Scoring

Maximo Application Suite33 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local4 (12.1%)
Network29 (87.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low31 (93.9%)
High2 (6.1%)
Unknown0 (0.0%)
User Interaction
None23 (69.7%)
Unknown0 (0.0%)
Required10 (30.3%)
Privileges Required
Low15 (45.5%)
High0 (0.0%)
None18 (54.5%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (33 CVEs).

33 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
IBM Maximo Application Suite 9.0.0 through 9.0.15 and 9.1.0 through 9.1.4 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the appl
Oct 28, 20259.833NONO
IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, 7.6.1.3 and the IBM Maximo Manage 8.3, 8.4 application in IBM Maximo Application Suite are vulnerable to CSV injection. IBM X-Force I
Jan 9, 20238.827NONO
IBM Maximo Application Suite 9.0 could allow an attacker with some level of access to elevate their privileges due to a security configuration vulnerability in Role-Based Access Co
May 6, 20258.825NONO
IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. Th
Sep 14, 20227.525NONO
IBM Maximo Application Suite 9.0 could allow an authenticated user to upload a file with dangerous types that could be executed by another user if opened.
Apr 5, 20258.024NONO
IBM Maximo Application Suite 8.10.10, 8.11.7, and 9.0 - Monitor Component is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could
Jan 25, 20258.824NONO
IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. By sending a specially crafted H
May 3, 20227.224NONO
IBM Maximo Application Suite 7.6.1.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to
Mar 14, 20248.223NONO
IBM Maximo Asset Management 7.6.1.3 and Manage Component 8.10 through 8.11 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauth
Jan 19, 20248.823NONO
IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. T
Feb 17, 20237.523NONO

Exploit Exposure

Signals from CVEs in this product scope (33 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (33 CVEs).

Media Mentions

Signals from CVEs in this product scope (33 CVEs).

Top CNAs Publishing CVEs For Maximo Application Suite

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.1.015.30.3%00
9.076.90.3%00
8.9.035.60.3%00
8.915.40.5%00
8.8.045.50.4%00
8.826.50.5%00
8.736.70.7%00
8.517.50.5%00
8.437.20.5%00
8.318.80.5%00
8.11.815.40.3%00
8.11.718.80.4%00
8.1146.50.4%00
8.10.1115.40.3%00
8.10.1018.80.4%00
8.1056.20.4%00
7.6.1.327.30.6%00