IBM Product Security Update Advisory (CVE-2025-36386)
Overview
We have released a security update to fix vulnerabilities in IBM products. Users of affected products are advised to update to the latest version.
Affected Products
CVE-2025-36386
IBM Maximo Application Suite – Manage Component versions: MAS 9.0.0 and earlier 9.0.15 and earlier, Manage 9.0.0 and earlier 9.0.17 and earlier
IBM Maximo Application Suite – Manage Component version: MAS 9.1.0 or later 9.1.4 or earlier, Manage 9.1.0 or later 9.1.4 or earlier
Resolved Vulnerabilities
Authentication bypass vulnerability in IBM Maximo Manage application Suite (CVE-2025-36386)
Vulnerability Patches
Vulnerability Patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.
CVE-2025-36386
IBM Maximo Application Suite – Manage Component Versions: Update as documented in the Referenced Sites [2][3]
References
[1] Security Bulletin: There is a vulnerability in the IBM Maximo Manage application in IBM Maximo Application Suite for Cognos Analytics
https://www.ibm.com/support/pages/node/7249416
[2] Fix Central
https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm%7ETivoli&product=ibm/Tivoli/I..
[3] Fix Central
https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm%7ETivoli&product=ibm/Tivoli/I..