Data Injection Vulnerability in IBM Maximo Application Suite Monitor Component
CVE-2025-14684

4MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
25 March 2026

What is CVE-2025-14684?

The IBM Maximo Application Suite Monitor Component versions 9.1, 9.0, 8.11, and 8.10 may be susceptible to a data injection vulnerability. This issue arises from improper handling of special elements when logging data, potentially allowing an unauthorized user to inject malicious data into system logs. This vulnerability could lead to compromised application integrity, making it essential for users to apply the necessary patches and monitor their environments.

Affected Version(s)

Maximo Application Suite - Monitor Component 9.1

Maximo Application Suite - Monitor Component 9.0

Maximo Application Suite - Monitor Component 8.11

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.