Impact
The reported vulnerability in IBM Maximo Application Suite 9.2, 9.1, and 9.0 allows attackers to capture authorization and session cookie values by directing users to an HTTP link or embedding such a link in a website. Because the Secure flag is not set, the cookies are transmitted over insecure connections, enabling traffic snooping and potential session hijacking. This flaw is categorized as CWE‑614, reflecting the risk of sensitive data exposure via insecure cookie handling.
Affected Systems
IBM Maximo Application Suite 9.2, 9.1, and 9.0 are affected. IBM has issued updated versions—9.2.1, 9.1.20, and 9.0.28—that remediate the missing Secure attribute on session and authorization cookies.
Risk and Exploitability
The CVSS base score of 4.3 indicates a moderate risk level, though no EPSS data is available and the vulnerability is not listed in the CISA KEV catalog. Likely exploitation requires social engineering or a malicious link; once a user follows an HTTP link, the cookie is transmitted in plain text, allowing an attacker to capture and replay it. The attack surface is limited to environments where HTTPS enforcement is lax, but the consequences include potential unauthorized access and data exposure.
OpenCVE Enrichment