Where
-Infinity
0

IBM Maximo Application Suite21 vulnerabilities

First published (updated )
Advisory
IBM-7282362

IBM MAS uses axios-1.15.2, protobufjs-8.0.1 and undici-7.26 which is vulnerable to multiple CVEs, and contains vulnerabilities related to missing Secure attribute on mas-redirect-uri cookie and weak HMAC Session Secret

Risk 22
Severity
4.3
First published (updated )

IBM MAS uses axios-1.15.2, protobufjs-8.0.1 and undici-7.26 which is vulnerable to multiple CVEs, and contains vulnerabilities related to missing Secure attribute on mas-redirect-uri cookie and weak HMAC Session Secret

Risk 27
Severity
5.3
First published (updated )

undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching

Risk 20
Severity
3.7
First published (updated )

undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse

Risk 20
Severity
3.7
First published (updated )

undici vulnerable to cross-user information disclosure via shared cache whitespace bypass

Risk 26
Severity
5.9
EPSS
0.36%
First published (updated )

undici vulnerable to HTTP header injection via Set-Cookie percent-decoding

Risk 26
Severity
5.9
EPSS
0.26%
First published (updated )

undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent

Risk 41
Severity
7.4
EPSS
0.46%
First published (updated )

undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse

Risk 79
Severity
8.8
First published (updated )

undici WebSocket client vulnerable to denial of service via fragment count bypass

Risk 43
Severity
7.5
First published (updated )

protobufjs: Memory amplification from preserved unknown fields in binary decode

Risk 27
Severity
5.3
First published (updated )

protobufjs: Denial of service through unbounded Any expansion during JSON conversion

Risk 43
Severity
7.5
First published (updated )

protobufjs: Schema-derived names can shadow runtime-significant properties

Risk 27
Severity
5.3
First published (updated )

Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection

Risk 43
Severity
7.5
First published (updated )

Axios: Allocation of Resources Without Limits or Throttling in axios

Risk 43
Severity
7.5
First published (updated )

Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter

Risk 43
Severity
8.2
First published (updated )

Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection

Risk 43
Severity
7.5
First published (updated )

Axios: Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`

Risk 64
Severity
8.7
First published (updated )

Axios: shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)

Risk 49
Severity
8.6
First published (updated )

Axios: DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions

Risk 54
Severity
8.2
First published (updated )

Axios: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix

Risk 27
Severity
5.3
First published (updated )

protobufjs: Denial of Service via unbounded recursive JSON descriptor expansion

Risk 43
Severity
7.5
First published (updated )

IBM Maximo Application Suite1 vulnerability

First published (updated )
Advisory
IBM-7268028

IBM Maximo Application Suite was vulnerable to because Cookie ltpatoken2_<workspace_name> was not set with secure flag

Risk 16
Severity
4.3
EPSS
0.01%
First published (updated )

IBM Maximo Application Suite - Monitor ComponentIBM Maximo Application Suite - Monitor Component uses Log Forging which is vulnerable to .

Risk 21
Severity
4
First published (updated )

IBM Maximo Application SuiteIBM Maximo Application Suite privilege escalation

Risk 79
Severity
8.8
First published (updated )

IBM Maximo Application Suite - Monitor Component1 vulnerability

First published (updated )
Advisory
IBM-7174946

IBM Maximo Application Suite cross-site scripting

Risk 35
Severity
5.4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

IBM Maximo Application Suite - Monitor Component1 vulnerability

First published (updated )
Advisory
IBM-7174956

IBM Maximo Application Suite cross-site scripting

Risk 38
Severity
6.1
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203