CVE-2026-15656
Received Received - Intake

IBM Maximo Application Suite Cookie Exposure Vulnerability

Vulnerability report for CVE-2026-15656, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-05

Last updated on: 2026-08-05

Assigner: IBM Corporation

Description

IBM Maximo Application Suite 9.2, 9.1, and 9.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-05
Last Modified
2026-08-05
Generated
2026-08-05
AI Q&A
2026-08-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
ibm maximo_application_suite 9.0
ibm maximo_application_suite 9.1
ibm maximo_application_suite 9.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-614 The Secure attribute for sensitive cookies in HTTPS sessions is not set.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

IBM Maximo Application Suite versions 9.2, 9.1, and 9.0 do not set the secure attribute on authorization tokens or session cookies. This means cookies are sent over unencrypted HTTP connections, allowing attackers to intercept them by tricking users into visiting malicious links or compromising websites.

Detection Guidance

To detect this vulnerability, inspect network traffic for unencrypted HTTP requests containing session cookies or authorization tokens. Check if cookies lack the Secure attribute in HTTP responses. Use browser developer tools to examine cookie attributes on IBM Maximo Application Suite pages.

Impact Analysis

Attackers could steal session cookies or authorization tokens by intercepting unencrypted traffic. This may lead to unauthorized access to user accounts, data theft, or session hijacking if users click malicious links or visit compromised sites.

Compliance Impact

This vulnerability violates data protection requirements under GDPR and HIPAA, which mandate encryption for sensitive data transmission. Failure to secure cookies may result in non-compliance, legal penalties, and reputational damage.

Mitigation Strategies

Immediately update IBM Maximo Application Suite to the latest version where the Secure attribute is enforced. Configure your web server to enforce HTTPS-only traffic. Set the Secure attribute on all session cookies and authorization tokens.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15656. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart