IBM Maximo Application Suite
cpe:2.3:a:ibm:maximo_application_suite:*:*:*:*:*:*:*
- >= 9.0.0, <= 9.0.15
- >= 9.1.0, <= 9.1.4
An authentication bypass vulnerability has been identified in IBM Maximo Application Suite versions 9.0.0 through 9.0.15 and 9.1.0 through 9.1.4. This vulnerability could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the application. The issue is particularly noted in the Maximo Manage component when used with standalone Cognos Analytics, where MXCSP is employed for integration.
Exploitation of this vulnerability could lead to unauthorized access to the application, allowing attackers to interact with the application as an authenticated user.
Users are advised to upgrade to the latest version of IBM Maximo Application Suite. Instructions for upgrading can be found on the IBM Fix Central website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.