IBM Maximo Application Suite 9.0.0 through 9.0.15 and 9.1.0 through 9.1.4 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the application.
History

Tue, 28 Oct 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Oct 2025 16:15:00 +0000

Type Values Removed Values Added
Description IBM Maximo Application Suite 9.0.0 through 9.0.15 and 9.1.0 through 9.1.4 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the application.
Title There is a vulnerability in the IBM Maximo Manage application in IBM Maximo Application Suite for Cognos Analytics
First Time appeared Ibm
Ibm maximo Application Suite
Weaknesses CWE-305
CPEs cpe:2.3:a:ibm:maximo_application_suite:9.0.15:*:*:*:*:*:*:*
cpe:2.3:a:ibm:maximo_application_suite:9.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:maximo_application_suite:9.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:maximo_application_suite:9.1.4:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm maximo Application Suite
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published: 2025-10-28T15:56:58.740Z

Updated: 2025-10-28T16:57:09.538Z

Reserved: 2025-04-15T21:16:57.301Z

Link: CVE-2025-36386

cve-icon Vulnrichment

Updated: 2025-10-28T16:57:05.997Z

cve-icon NVD

Status : Received

Published: 2025-10-28T16:15:38.107

Modified: 2025-10-28T16:15:38.107

Link: CVE-2025-36386

cve-icon Redhat

No data.