First published: Fri Sep 06 2024(Updated: )
IBM Maximo Application Suite - Manage Component 8.10, 8.11, and 9.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information using man in the middle techniques.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Maximo Application Suite | =8.10 | |
IBM Maximo Application Suite | =8.11 | |
IBM Maximo Application Suite | =9.0 | |
IBM Maximo Manage Application | <=MAS 8.10 - Manage 8.6.16 | |
IBM Maximo Manage Application | <=MAS 8.11 - Manage 8.7.10 | |
IBM Maximo Manage Application | <=MAS 9.0.0 - Manage 9.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-37068 is classified as a high severity vulnerability due to the potential for attackers to decrypt sensitive data.
To fix CVE-2024-37068, it is recommended to update to a version of IBM Maximo Application Suite - Manage Component that is not affected by the weak encryption algorithms.
CVE-2024-37068 affects IBM Maximo Application Suite - Manage Component versions 8.10, 8.11, and 9.0 up to certain patch levels.
CVE-2024-37068 is associated with man-in-the-middle attacks where an attacker can exploit weaker cryptographic algorithms.
CVE-2024-37068 could allow attackers to decrypt highly sensitive information managed by the IBM Maximo Application Suite.