IBM Maximo Application Suite Authentication Bypass Vulnerability Allowing Unauthorized Access

Vulnerability

An authentication bypass vulnerability has been identified in IBM Maximo Application Suite versions 9.0.0 through 9.0.15 and 9.1.0 through 9.1.4. This vulnerability could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the application. The issue is particularly noted in the Maximo Manage component when used with standalone Cognos Analytics, where MXCSP is employed for integration.

Impact

Exploitation of this vulnerability could lead to unauthorized access to the application, allowing attackers to interact with the application as an authenticated user.

Remediation

Users are advised to upgrade to the latest version of IBM Maximo Application Suite. Instructions for upgrading can be found on the IBM Fix Central website.

Added: Oct 28, 2025, 4:20 PM
Updated: Oct 28, 2025, 4:20 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
5.0
exploitability
7.4
remediation
7.7
relevance
0.8
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.