IBM Maximo Application Suite 8.10.10, 8.11.7, and 9.0 - Monitor Component is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
| Software | From | Fixed in |
|---|---|---|
| ibm / maximo_application_suite | 9.0 | 9.0.x |
| ibm / maximo_application_suite | 8.10.10 | 8.10.10.x |
| ibm / maximo_application_suite | 8.11.7 | 8.11.7.x |