CVE-2025-2986
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Published Apr 25, 2025
Updated: Apr 29, 2025
CWE ID 79
Summary
CVE-2025-2986 is a stored cross-site scripting (XSS) vulnerability affecting IBM Maximo Asset Management version 7.6.1.3. A privileged user can exploit this issue by embedding malicious JavaScript code into the Web UI. This code is then executed in a user's browser when they view a manipulated page, potentially leading to the disclosure of session credentials within a trusted environment.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- IBM Maximo Asset Management
Affected Vendors
- IBM