Description
IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with session data due to the use of a weak HMAC session signing secret.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Remediated Product(s)Version(s)IBM Maximo Application Suite9.2.1IBM Maximo Application Suite9.1.20IBM Maximo Application Suite9.0.28
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7282362 |
|
History
Wed, 05 Aug 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with session data due to the use of a weak HMAC session signing secret. | |
| Title | IBM MAS uses axios-1.15.2, protobufjs-8.0.1 and undici-7.26 which is vulnerable to multiple CVEs, and contains vulnerabilities related to missing Secure attribute on mas-redirect-uri cookie and weak HMAC Session Secret | |
| First Time appeared |
Ibm
Ibm maximo Application Suite |
|
| Weaknesses | CWE-330 | |
| CPEs | cpe:2.3:a:ibm:maximo_application_suite:9.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:maximo_application_suite:9.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:maximo_application_suite:9.1.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:maximo_application_suite:9.1:*:*:*:*:*:*:* cpe:2.3:a:ibm:maximo_application_suite:9.2.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:maximo_application_suite:9.2:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm maximo Application Suite |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-08-05T16:04:14.743Z
Reserved: 2026-07-31T20:03:37.213Z
Link: CVE-2026-18531
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-05T17:45:16Z
Weaknesses