CVE-2024-35148
CVSS 3.1 Score 6.3 of 10 (medium)
Details
Published Jan 25, 2025
CWE ID 89
Summary
CVE-2024-35148 is a newly disclosed vulnerability affecting the Monitor Component in IBM Maximo Application Suite versions 8.10.10, 8.11.7, and 9.0. This issue enables a remote attacker to inject malicious SQL statements into the application, potentially granting unauthorized access to the back-end database. Attackers can manipulate data, add new records, modify existing information, or even delete sensitive data. IBM urges users to apply the available patches to mitigate this security risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- IBM Corporation