CVE-2024-35150

EUVD-2024-35549
IBM Maximo Application Suite 8.10.12, 8.11.0, 9.0.1, and 9.1.0 - Monitor Component does not neutralize output that is written to logs, which could allow an attacker to inject false log entries.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
ibmCNA
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 27%
Affected Products (NVD)
VendorProductVersion
ibmmaximo_application_suite
8.10.12 ≤
𝑥
< 8.10.15
ibmmaximo_application_suite
8.11 ≤
𝑥
< 8.11.13
ibmmaximo_application_suite
9.0.1 ≤
𝑥
< 9.0.5
ibmmaximo_application_suite
9.1.0
𝑥
= Vulnerable software versions