Maximo Application Suite
Vendor:
First CVE: Aug 27, 2021 · Active for 4 years
33
Total CVEs
More Total CVEs than 96% of tracked products
5.5
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 29% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Maximo Application Suite over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 27, 2021
4 years ago
Most Recent CVE
Apr 1, 2026
114 days ago
CVE Severity & Scoring
Maximo Application Suite33 CVEs
58%
36%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local4 (12.1%)
Network29 (87.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low31 (93.9%)
High2 (6.1%)
Unknown0 (0.0%)
User Interaction
None23 (69.7%)
Unknown0 (0.0%)
Required10 (30.3%)
Privileges Required
Low15 (45.5%)
High0 (0.0%)
None18 (54.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (33 CVEs).
33 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-36386CRITICAL IBM Maximo Application Suite 9.0.0 through 9.0.15 and 9.1.0 through 9.1.4 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the appl | Oct 28, 2025 | 9.8 | 33 | NO | NO |
CVE-2022-35281HIGH IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, 7.6.1.3 and the IBM Maximo Manage 8.3, 8.4 application in IBM Maximo Application Suite are vulnerable to CSV injection. IBM X-Force I | Jan 9, 2023 | 8.8 | 27 | NO | NO |
CVE-2025-2898HIGH IBM Maximo Application Suite 9.0 could allow an attacker with some level of access to elevate their privileges due to a security configuration vulnerability in Role-Based Access Co | May 6, 2025 | 8.8 | 25 | NO | NO |
CVE-2021-38924HIGH IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. Th | Sep 14, 2022 | 7.5 | 25 | NO | NO |
CVE-2025-1500HIGH IBM Maximo Application Suite 9.0 could allow an authenticated user to upload a file with dangerous types that could be executed by another user if opened. | Apr 5, 2025 | 8.0 | 24 | NO | NO |
CVE-2024-35148HIGH IBM Maximo Application Suite 8.10.10, 8.11.7, and 9.0 - Monitor Component is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could | Jan 25, 2025 | 8.8 | 24 | NO | NO |
CVE-2021-29854HIGH IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. By sending a specially crafted H | May 3, 2022 | 7.2 | 24 | NO | NO |
CVE-2024-27266HIGH IBM Maximo Application Suite 7.6.1.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to | Mar 14, 2024 | 8.2 | 23 | NO | NO |
CVE-2023-47718HIGH IBM Maximo Asset Management 7.6.1.3 and Manage Component 8.10 through 8.11 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauth | Jan 19, 2024 | 8.8 | 23 | NO | NO |
CVE-2022-41734HIGH IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. T | Feb 17, 2023 | 7.5 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (33 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (33 CVEs).
Media Mentions
Signals from CVEs in this product scope (33 CVEs).
Top CNAs Publishing CVEs For Maximo Application Suite
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.1.0 | 1 | 5.3 | 0.3% | 0 | 0 |
| 9.0 | 7 | 6.9 | 0.3% | 0 | 0 |
| 8.9.0 | 3 | 5.6 | 0.3% | 0 | 0 |
| 8.9 | 1 | 5.4 | 0.5% | 0 | 0 |
| 8.8.0 | 4 | 5.5 | 0.4% | 0 | 0 |
| 8.8 | 2 | 6.5 | 0.5% | 0 | 0 |
| 8.7 | 3 | 6.7 | 0.7% | 0 | 0 |
| 8.5 | 1 | 7.5 | 0.5% | 0 | 0 |
| 8.4 | 3 | 7.2 | 0.5% | 0 | 0 |
| 8.3 | 1 | 8.8 | 0.5% | 0 | 0 |
| 8.11.8 | 1 | 5.4 | 0.3% | 0 | 0 |
| 8.11.7 | 1 | 8.8 | 0.4% | 0 | 0 |
| 8.11 | 4 | 6.5 | 0.4% | 0 | 0 |
| 8.10.11 | 1 | 5.4 | 0.3% | 0 | 0 |
| 8.10.10 | 1 | 8.8 | 0.4% | 0 | 0 |
| 8.10 | 5 | 6.2 | 0.4% | 0 | 0 |
| 7.6.1.3 | 2 | 7.3 | 0.6% | 0 | 0 |