CVE-2024-35150: IBM Maximo Application Suite log manipulation
IBM Maximo Application Suite - Monitor Component does not neutralize output that is written to logs, which could allow an attacker to inject false log entries.
Other sources
IBM Maximo Application Suite 8.10.12, 8.11.0, 9.0.1, and 9.1.0 - Monitor Component does not neutralize output that is written to logs, which could allow an attacker to inject false log entries.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35150?
CVE-2024-35150 is classified as a high severity vulnerability.
How do I fix CVE-2024-35150?
To mitigate CVE-2024-35150, update the IBM Maximo Application Suite to the latest version that addresses this issue.
Which versions of IBM Maximo Application Suite are affected by CVE-2024-35150?
CVE-2024-35150 affects IBM Maximo Application Suite versions 8.10.12, 8.11.0, 9.0.1, and 9.1.0.
What type of vulnerability is CVE-2024-35150?
CVE-2024-35150 is an output neutralization vulnerability that allows injection of false log entries.
What component is impacted by CVE-2024-35150?
CVE-2024-35150 impacts the Monitor Component of the IBM Maximo Application Suite.