← Vulnerability feed

Vulnerability record · CVE-2024-37068 · published 7 September 2024

CVE-2024-37068: Ibm maximo application suite broken cryptographic algorithm vulnerability

Ibm · Maximo Application Suite

IBM Maximo Application Suite - Manage Component 8.10, 8.11, and 9.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information using man in the middle techniques.

7.5 CVSS 3.1 High EPSS 0.25% · top 85.6% CWE-327 · Broken cryptographic algorithm
7.5CVSS 3.1 base score
0.25%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

IBM Maximo Application Suite - Manage Component 8.10, 8.11, and 9.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information using man in the middle techniques.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-37068 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-36386Ibm maximo application suite vulnerabilityIBM Maximo Application Suite 9.0.0 through 9.0.15 and 9.1.0 through 9.1.4 could allow a remote attacker to bypass authentication mechanisms and gain …EPSS 0.52%8.8CVE-2025-2898Ibm maximo application suite vulnerabilityIBM Maximo Application Suite 9.0 could allow an attacker with some level of access to elevate their privileges due to a security configuration vulner…EPSS 0.33%8.8CVE-2024-35148Ibm maximo application suite sql injection vulnerabilityIBM Maximo Application Suite 8.10.10, 8.11.7, and 9.0 - Monitor Component is vulnerable to SQL injection. A remote attacker could send specially craf…EPSS 0.36%8.8CVE-2023-47718Ibm maximo application suite cross-site request forgery vulnerabilityIBM Maximo Asset Management 7.6.1.3 and Manage Component 8.10 through 8.11 is vulnerable to cross-site request forgery which could allow an attacker …EPSS 0.30%8.8CVE-2022-35281Ibm maximo application suite csv injection vulnerabilityIBM Maximo Asset Management 7.6.1.1, 7.6.1.2, 7.6.1.3 and the IBM Maximo Manage 8.3, 8.4 application in IBM Maximo Application Suite are vulnerable t…EPSS 0.51%8.2CVE-2024-27266Ibm maximo application suite xml external entity (xxe) vulnerabilityIBM Maximo Application Suite 7.6.1.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could…EPSS 0.85%8.0CVE-2025-1500Ibm maximo application suite unrestricted file upload vulnerabilityIBM Maximo Application Suite 9.0 could allow an authenticated user to upload a file with dangerous types that could be executed by another user if op…EPSS 0.28%7.5CVE-2024-22328Ibm maximo application suite path traversal vulnerabilityIBM Maximo Application Suite 8.10 and 8.11 could allow a remote attacker to traverse directories on the system. An attacker could send a specially cr…EPSS 0.84%

Source: NIST National Vulnerability Database (record CVE-2024-37068), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.