SB2025101015 - IBM Maximo Application Suite - Visual Inspection Component update for Flask



SB2025101015 - IBM Maximo Application Suite - Visual Inspection Component update for Flask

Published: October 10, 2025

Security Bulletin ID SB2025101015
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Cryptographic issues (CVE-ID: CVE-2025-47278)

The vulnerability allows a local user to bypass implemented security restrictions.

The vulnerability exists due to the way fallback key configuration was handled. The application used the last fallback key for signing, rather than the current signing key, which could potentially lead to data tampering.


Remediation

Install update from vendor's website.