CVE-2025-2986: IBM Maximo Asset Management cross-site scripting
IBM Maximo Asset Management 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM Maximo Asset Management is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2986?
CVE-2025-2986 is classified as a medium severity stored cross-site scripting vulnerability.
How do I fix CVE-2025-2986?
To fix CVE-2025-2986, upgrade IBM Maximo Asset Management to a version later than 7.6.1.3 that includes the security patch.
Who is affected by CVE-2025-2986?
CVE-2025-2986 affects users of IBM Maximo Asset Management version 7.6.1.3 and earlier.
What potential impact does CVE-2025-2986 have?
CVE-2025-2986 can lead to the disclosure of sensitive user credentials and alteration of the intended functionality in the application.
Is CVE-2025-2986 a privilege escalation vulnerability?
CVE-2025-2986 is not a privilege escalation vulnerability but allows a privileged user to execute arbitrary JavaScript in the Web UI.