Known vulnerabilities in Maximo Application Suite - Predict Component

Software CPE: cpe:2.3:a:ibm_corporation:maximo_application_suite_-_predict_component:*:*:*:*:*:*:*:*
Total vulnerabilities: 71
Public exploits: 3
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Maximo Application Suite - Predict Component Maximo Application Suite - Predict Component is affected by 71 known vulnerabilities: 5 high, 42 medium, 24 low Critical High Medium Low

Vulnerabilities (71)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU137405 - Command injection
CVE-2026-7246
CWE-77 Low
No
No
9.0.17, 9.1.10, 9.2.1 14.07.2026 SB2026071423
SB2026071424
SB2026071440
and 9 more
#VU127955 - Allocation of Resources Without Limits or Throttling
CVE-2026-22815
CWE-770 Medium
No
No
9.2.1 26.04.2026 SB2026042605
SB2026050302
SB2026050303
and 6 more
#VU127954 - Resource exhaustion
CVE-2026-34513
CWE-400 Medium
No
No
9.2.1 26.04.2026 SB2026042605
SB2026050302
SB2026050303
and 7 more
#VU127953 - Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVE-2026-34514
CWE-93 Medium
No
No
9.2.1 26.04.2026 SB2026042605
SB2026050302
SB2026050303
and 7 more
#VU127952 - Server-Side Request Forgery (SSRF)
CVE-2026-34515
CWE-918 Medium
No
No
9.2.1 26.04.2026 SB2026042605
SB2026070226
SB2026080434
#VU127951 - Improper input validation
CVE-2026-34516
CWE-20 Medium
No
No
9.2.1 26.04.2026 SB2026042605
SB2026050302
SB2026050303
and 7 more
#VU127950 - Resource exhaustion
CVE-2026-34517
CWE-400 Medium
No
No
9.2.1 26.04.2026 SB2026042605
SB2026050302
SB2026050303
and 6 more
#VU127949 - Exposure of sensitive information to an unauthorized actor
CVE-2026-34518
CWE-200 Medium
No
No
9.2.1 26.04.2026 SB2026042605
SB2026050302
SB2026050303
and 6 more
#VU127948 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
CVE-2026-34519
CWE-113 Medium
No
No
9.2.1 26.04.2026 SB2026042605
SB2026050302
SB2026050303
and 6 more
#VU127947 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
CVE-2026-34520
CWE-113 Medium
No
No
9.2.1 26.04.2026 SB2026042605
SB2026050302
SB2026050303
and 6 more
#VU127946 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2026-34525
CWE-444 Low
No
No
9.2.1 26.04.2026 SB2026042605
SB2026050302
SB2026050303
and 6 more
#VU125338 - Improper Certificate Validation
CVE-2026-34073
CWE-295 Medium
No
No
8.8.15, 8.9.17, 9.0.14, 9.1.7 08.04.2026 SB2026040896
SB20260408119
SB20260408120
and 8 more
#VU120998 - Resource exhaustion
CVE-2025-69229
CWE-400 Medium
No
No
9.0.17, 9.1.10, 9.2.1 06.01.2026 SB2026010643
SB2026012919
SB20260216150
and 10 more
#VU120997 - Resource Management Errors
CVE-2025-69230
CWE-399 Low
No
No
9.0.17, 9.1.10, 9.2.1 06.01.2026 SB2026010643
SB2026030633
SB2026031147
and 4 more
#VU120996 - Resource exhaustion
CVE-2025-69228
CWE-400 Medium
No
No
9.0.17, 9.1.10, 9.2.1 06.01.2026 SB2026010643
SB2026012920
SB20260216150
and 9 more
#VU120995 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2025-69227
CWE-835 Medium
No
No
9.0.17, 9.1.10, 9.2.1 06.01.2026 SB2026010643
SB2026012920
SB20260216150
and 9 more
#VU120994 - Exposure of sensitive information to an unauthorized actor
CVE-2025-69226
CWE-200 Low
No
No
9.0.17, 9.1.10, 9.2.1 06.01.2026 SB2026010643
SB20260216150
SB2026030633
and 8 more
#VU120993 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2025-69225
CWE-444 Low
No
No
9.0.17, 9.1.10, 9.2.1 06.01.2026 SB2026010643
SB2026012920
SB20260216150
and 9 more
#VU120992 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2025-69224
CWE-444 Low
No
No
9.0.17, 9.1.10, 9.2.1 06.01.2026 SB2026010643
SB20260216150
SB2026030633
and 8 more
#VU120990 - Improper Handling of Highly Compressed Data (Data Amplification)
CVE-2025-69223
CWE-409 Medium
No
No
9.0.17, 9.1.10, 9.2.1 06.01.2026 SB2026010643
SB2026012661
SB2026012855
and 15 more


Showing elements 1 - 20 out of 71