CVE-2024-35148: IBM Maximo Application Suite SQL injection
IBM Maximo Application Suite - Monitor Component is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
Other sources
IBM Maximo Application Suite 8.10.10, 8.11.7, and 9.0 - Monitor Component is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35148?
CVE-2024-35148 has a high severity rating as it allows remote attackers to execute SQL injection attacks.
How do I fix CVE-2024-35148?
To fix CVE-2024-35148, update your IBM Maximo Application Suite to the latest version provided by IBM.
What versions of IBM Maximo Application Suite are affected by CVE-2024-35148?
CVE-2024-35148 affects IBM Maximo Application Suite versions up to 9.0.0 as well as the Monitor Component versions 8.10.10 and 8.11.7.
Can CVE-2024-35148 allow data manipulation?
Yes, CVE-2024-35148 could allow an attacker to view, add, modify, or delete information in the back-end database.
Is there a workaround for CVE-2024-35148?
While updating is the recommended solution, implementing strong input validation can mitigate the risk of SQL injection in CVE-2024-35148.