Known vulnerabilities in Maximo Application Suite - Predict Component

Software CPE: cpe:2.3:a:ibm_corporation:maximo_application_suite_-_predict_component:*:*:*:*:*:*:*:*
Total vulnerabilities: 74
Public exploits: 3
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Maximo Application Suite - Predict Component Maximo Application Suite - Predict Component is affected by 74 known vulnerabilities: 5 high, 43 medium, 26 low Critical High Medium Low

Vulnerabilities (74)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU137405 - Command injection
CVE-2026-7246
CWE-77 Low
No
No
9.0.17, 9.1.10, 9.2.1 14.07.2026 SB2026071423
SB2026071424
SB2026071440
and 13 more
#VU137280 - Improper Handling of Unicode Encoding
CVE-2026-59890
CWE-176 Medium
No
No
- 09.07.2026 SB2026070950
SB2026080371
SB2026090327
#VU132041 - Resource exhaustion
CVE-2026-4410
CWE-400 Low
No
No
9.0.18, 9.1.11, 9.2.2 21.05.2026 SB2026052124
SB2026060911
SB2026060912
and 12 more
#VU132031 - Security Features
CVE-2026-5516
CWE-254 Low
No
No
9.0.18, 9.1.11, 9.2.2 21.05.2026 SB2026052115
SB20260626104
SB2026071327
and 13 more
#VU127955 - Allocation of Resources Without Limits or Throttling
CVE-2026-22815
CWE-770 Medium
No
No
9.2.1 26.04.2026 SB2026042605
SB2026050302
SB2026050303
and 6 more
#VU127954 - Resource exhaustion
CVE-2026-34513
CWE-400 Medium
No
No
9.2.1 26.04.2026 SB2026042605
SB2026050302
SB2026050303
and 7 more
#VU127953 - Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVE-2026-34514
CWE-93 Medium
No
No
9.2.1 26.04.2026 SB2026042605
SB2026050302
SB2026050303
and 7 more
#VU127952 - Server-Side Request Forgery (SSRF)
CVE-2026-34515
CWE-918 Medium
No
No
9.2.1 26.04.2026 SB2026042605
SB2026070226
SB2026080434
#VU127951 - Improper input validation
CVE-2026-34516
CWE-20 Medium
No
No
9.2.1 26.04.2026 SB2026042605
SB2026050302
SB2026050303
and 7 more
#VU127950 - Resource exhaustion
CVE-2026-34517
CWE-400 Medium
No
No
9.2.1 26.04.2026 SB2026042605
SB2026050302
SB2026050303
and 6 more
#VU127949 - Exposure of sensitive information to an unauthorized actor
CVE-2026-34518
CWE-200 Medium
No
No
9.2.1 26.04.2026 SB2026042605
SB2026050302
SB2026050303
and 6 more
#VU127948 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
CVE-2026-34519
CWE-113 Medium
No
No
9.2.1 26.04.2026 SB2026042605
SB2026050302
SB2026050303
and 6 more
#VU127947 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
CVE-2026-34520
CWE-113 Medium
No
No
9.2.1 26.04.2026 SB2026042605
SB2026050302
SB2026050303
and 6 more
#VU127946 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2026-34525
CWE-444 Low
No
No
9.2.1 26.04.2026 SB2026042605
SB2026050302
SB2026050303
and 6 more
#VU120996 - Resource exhaustion
CVE-2025-69228
CWE-400 Medium
No
No
9.0.17, 9.1.10, 9.2.1 06.01.2026 SB2026010643
SB2026012920
SB20260216150
and 9 more
#VU120995 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2025-69227
CWE-835 Medium
No
No
9.0.17, 9.1.10, 9.2.1 06.01.2026 SB2026010643
SB2026012920
SB20260216150
and 9 more
#VU120994 - Exposure of sensitive information to an unauthorized actor
CVE-2025-69226
CWE-200 Low
No
No
9.0.17, 9.1.10, 9.2.1 06.01.2026 SB2026010643
SB20260216150
SB2026030633
and 8 more
#VU120993 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2025-69225
CWE-444 Low
No
No
9.0.17, 9.1.10, 9.2.1 06.01.2026 SB2026010643
SB2026012920
SB20260216150
and 9 more
#VU120992 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2025-69224
CWE-444 Low
No
No
9.0.17, 9.1.10, 9.2.1 06.01.2026 SB2026010643
SB20260216150
SB2026030633
and 8 more
#VU120990 - Improper Handling of Highly Compressed Data (Data Amplification)
CVE-2025-69223
CWE-409 Medium
No
No
9.0.17, 9.1.10, 9.2.1 06.01.2026 SB2026010643
SB2026012661
SB2026012855
and 15 more


Showing elements 1 - 20 out of 74