Session Cookie Vulnerability in IBM Maximo Application Suite
CVE-2026-15656
4.3MEDIUM
What is CVE-2026-15656?
The IBM Maximo Application Suite (versions 9.2, 9.1, and 9.0) has a security vulnerability where authorization tokens and session cookies do not have the secure attribute set. This oversight can allow attackers to capture cookie values through crafted HTTP links. If a user unknowingly clicks on such a link or visits an infected site, their session cookies may be transmitted via insecure channels, potentially exposing sensitive data. It is crucial for users to be aware and for organizations to apply appropriate patches to safeguard against such risks.
Affected Version(s)
Maximo Application Suite 9.2
Maximo Application Suite 9.1
Maximo Application Suite 9.0