Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-35209 | IBM Maximo Application Suite - Monitor Component 8.10.11, 8.11.8, and 9.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. |
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7174946 |
|
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 08 Jul 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:ibm:maximo_application_suite:9.0:*:*:*:*:*:*:* |
Wed, 06 Nov 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 06 Nov 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Maximo Application Suite - Monitor Component 8.10.11, 8.11.8, and 9.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Title | IBM Maximo Application Suite cross-site scripting | |
| First Time appeared |
Ibm
Ibm maximo Application Suite |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:ibm:maximo_application_suite:8.10.11:*:*:*:*:*:*:* cpe:2.3:a:ibm:maximo_application_suite:8.11.8:*:*:*:*:*:*:* cpe:2.3:a:ibm:maximo_application_suite:9.0.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm maximo Application Suite |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2024-11-06T15:12:57.373Z
Reserved: 2024-05-09T16:27:36.634Z
Link: CVE-2024-35146
Updated: 2024-11-06T15:12:50.886Z
Status : Analyzed
Published: 2024-11-06T15:15:19.247
Modified: 2025-07-08T20:29:54.267
Link: CVE-2024-35146
No data.
OpenCVE Enrichment
No data.
EUVD