CVE-2025-14684 PUBLISHED

IBM Maximo Application Suite - Monitor Component uses Log Forging which is vulnerable to .

Assigner: ibm
Reserved: 13.12.2025 Published: 25.03.2026 Updated: 25.03.2026

IBM Maximo Application Suite - Monitor Component 9.1, 9.0, 8.11, and 8.10 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS Score: 4

Product Status

Vendor IBM
Product Maximo Application Suite - Monitor Component
Versions
  • Version 9.1 is affected
  • Version 9.0 is affected
  • Version 8.11 is affected
  • Version 8.10 is affected

Solutions

Remediated Product(s)Version(s)IBM Maximo Application Suite - Monitor Component9.1.6 (available from the Catalog under Update Available) https://www.ibm.com/docs/en/mas-cd/continuous-delivery IBM Maximo Application Suite - Monitor Component9.0.16 (available from the Catalog under Update Available) https://www.ibm.com/docs/en/mas-cd/continuous-delivery IBM Maximo Application Suite - Monitor Component8.11.24 (available from the Catalog under Update Available) https://www.ibm.com/docs/en/mas-cd/continuous-delivery IBM Maximo Application Suite - Monitor Component8.10.26 (available from the Catalog under Update Available) https://www.ibm.com/docs/en/mas-cd/continuous-delivery

References

Problem Types

  • CWE-117 Improper Output Neutralization for Logs CWE