CVE-2025-2898: IBM Maximo Application Suite privilege escalation
IBM Maximo Application Suite 9.0 could allow an attacker with some level of access to elevate their privileges due to a security configuration vulnerability in Role-Based Access Control (RBAC) configurations.
Other sources
IBM Maximo Application Suite could allow an attacker with some level of access to elevate their privileges due to a security configuration vulnerability in Role-Based Access Control (RBAC) configurations.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2898?
CVE-2025-2898 has been rated as a medium severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2025-2898?
To fix CVE-2025-2898, review and update the Role-Based Access Control configurations in IBM Maximo Application Suite 9.0.
Who is affected by CVE-2025-2898?
CVE-2025-2898 affects users of IBM Maximo Application Suite 9.0 that utilize Role-Based Access Control.
What type of vulnerability is CVE-2025-2898?
CVE-2025-2898 is a security configuration vulnerability related to Role-Based Access Control.
Can CVE-2025-2898 be exploited remotely?
CVE-2025-2898 could potentially be exploited by an attacker with some level of access to the IBM Maximo Application Suite.