IBM Maximo Application Suite - Monitor Component 9.1, 9.0, 8.11, and 8.10 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7267481 |
|
History
Sat, 28 Mar 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 26 Mar 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ibm maximo Application Suite - Monitor Component
|
|
| Vendors & Products |
Ibm maximo Application Suite - Monitor Component
|
Wed, 25 Mar 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Maximo Application Suite - Monitor Component 9.1, 9.0, 8.11, and 8.10 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files. | |
| Title | IBM Maximo Application Suite - Monitor Component uses Log Forging which is vulnerable to . | |
| First Time appeared |
Ibm
Ibm maximo Application Suite Monitor Component |
|
| Weaknesses | CWE-117 | |
| CPEs | cpe:2.3:a:ibm:maximo_application_suite___monitor_component:8.10.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:maximo_application_suite___monitor_component:8.10:*:*:*:*:*:*:* cpe:2.3:a:ibm:maximo_application_suite___monitor_component:8.11.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:maximo_application_suite___monitor_component:8.11:*:*:*:*:*:*:* cpe:2.3:a:ibm:maximo_application_suite___monitor_component:9.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:maximo_application_suite___monitor_component:9.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:maximo_application_suite___monitor_component:9.1.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:maximo_application_suite___monitor_component:9.1:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm maximo Application Suite Monitor Component |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-03-28T01:49:31.469Z
Reserved: 2025-12-13T20:24:32.826Z
Link: CVE-2025-14684
Updated: 2026-03-28T01:49:23.106Z
Status : Awaiting Analysis
Published: 2026-03-25T22:16:18.660
Modified: 2026-03-26T15:13:15.790
Link: CVE-2025-14684
No data.