IBM Maximo Application Suite 8.10.10, 8.11.7, and 9.0 - Monitor Component is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
CVE ID: CVE-2024-35148
CVSS Base Severity: MEDIUM
CVSS Base Score: 6.3
Vendor: IBM
Product: Maximo Application Suite
EPSS Score: 0.04% (probability of being exploited)
EPSS Percentile: 15.87% (scored less or equal to compared to others)
EPSS Date: 2025-02-23 (when was this score calculated)