First published: Mon Apr 21 2025(Updated: )
IBM Maximo Asset Management 7.6.1.3 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Maximo Asset Management | ||
IBM Maximo Asset Management | <=7.6.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-2987 is considered a high severity vulnerability due to its potential for server-side request forgery allowing unauthorized requests.
To mitigate CVE-2025-2987, upgrade IBM Maximo Asset Management to version 7.6.1.4 or later.
IBM Maximo Asset Management versions up to and including 7.6.1.3 are affected by CVE-2025-2987.
CVE-2025-2987 may allow an authenticated attacker to perform unauthorized requests, which could lead to network enumeration and further attacks.
Yes, an authenticated attacker can exploit CVE-2025-2987 to send unauthorized requests from the system.