First published: Fri Apr 25 2025(Updated: )
IBM Maximo Asset Management 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Maximo Asset Management | ||
IBM Maximo Asset Management | <=7.6.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-2986 is classified as a medium severity stored cross-site scripting vulnerability.
To fix CVE-2025-2986, upgrade IBM Maximo Asset Management to a version later than 7.6.1.3 that includes the security patch.
CVE-2025-2986 affects users of IBM Maximo Asset Management version 7.6.1.3 and earlier.
CVE-2025-2986 can lead to the disclosure of sensitive user credentials and alteration of the intended functionality in the application.
CVE-2025-2986 is not a privilege escalation vulnerability but allows a privileged user to execute arbitrary JavaScript in the Web UI.