CVE-2025-36386: There is a vulnerability in the IBM Maximo Manage application in IBM Maximo Application Suite for Cognos Analytics
IBM Maximo Application Suite 9.0.0 through 9.0.15 and 9.1.0 through 9.1.4 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the application.
Other sources
IBM Maximo Application Suite could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the application.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36386?
CVE-2025-36386 is classified as a high severity vulnerability due to the potential for unauthorized access.
How do I fix CVE-2025-36386?
To fix CVE-2025-36386, upgrade to IBM Maximo Application Suite version 9.1.5 or later, as it addresses the authentication bypass issue.
What versions of IBM Maximo Application Suite are affected by CVE-2025-36386?
CVE-2025-36386 affects IBM Maximo Application Suite versions 9.0.0 through 9.0.15 and 9.1.0 through 9.1.4.
Can CVE-2025-36386 be exploited remotely?
Yes, CVE-2025-36386 can be exploited remotely, allowing attackers to bypass authentication mechanisms.
Is CVE-2025-36386 related to any other IBM products?
CVE-2025-36386 may also impact components associated with IBM Maximo Manage and IBM Cognos Analytics.