CVE-2026-18531
5.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Summary
IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with session data due to the use of a weak HMAC session signing secret.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| IBM | Maximo Application Suite | 9.2 | affected |
| IBM | Maximo Application Suite | 9.1 | affected |
| IBM | Maximo Application Suite | 9.0 | affected |
Weaknesses
- CWE-330: CWE-330 Use of Insufficiently Random Values
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.