Impact
An attacker can manipulate the session data of IBM Maximo Application Suite because the application signs session cookies with a weak HMAC secret. By forging the signature, the attacker can alter session contents, potentially impersonating other users or elevating privileges. The weakness is a classic example of sensitive data exposure due to inadequate cryptographic protection. The risk is limited to the scope of the affected application and the data stored in its sessions.
Affected Systems
IBM Maximo Application Suite versions 9.2, 9.1, and 9.0 are affected. The patch releases that address this issue are IBM Maximo Application Suite 9.2.1, 9.1.20, and 9.0.28. Administrators of the corresponding product versions should verify that the installed version matches one of the patched releases.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity vulnerability; the EPSS score is not available, so the current likelihood of exploitation is unknown, but the weakness could be actively abused if an attacker discovers it. The vulnerability is not listed in CISA KEV, indicating that no widely known exploits have been reported publicly. The inferred attack vector is likely via standard web requests to the application, as the flaw involves tampering with HTTP session cookies.
OpenCVE Enrichment