CVE-2025-14684: IBM Maximo Application Suite - Monitor Component uses Log Forging which is vulnerable to .
IBM Maximo Application Suite - Monitor Component 9.1, 9.0, 8.11, and 8.10 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.
Other sources
IBM Maximo Application Suite - Monitor Component could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14684?
CVE-2025-14684 has a medium severity rating due to its potential for unauthorized access through log forging vulnerabilities.
How do I fix CVE-2025-14684?
To fix CVE-2025-14684, apply the recommended patches provided by IBM for the affected versions of Maximo Application Suite - Monitor Component.
Which versions of IBM Maximo Application Suite - Monitor Component are affected by CVE-2025-14684?
CVE-2025-14684 affects IBM Maximo Application Suite - Monitor Component versions 9.1, 9.0, 8.11, and 8.10.
What type of attack does CVE-2025-14684 allow?
CVE-2025-14684 allows unauthorized users to inject data into log messages, which can lead to further exploitation.
Is there a workaround for CVE-2025-14684?
Currently, there are no known workarounds for CVE-2025-14684, and updating to the patched versions is recommended.