CVE-2025-2987
CVSS 3.1 Score 3.8 of 10 (low)
Details
Published Apr 22, 2025
Updated: Apr 23, 2025
CWE ID 918
Summary
CVE-2025-2987 refers to a server-side request forgery (SSRF) vulnerability affecting IBM Maximo Asset Management version 7.6.1.3. An authenticated attacker can exploit this weakness to send unauthorized requests from the system, potentially leading to network enumeration and facilitating further attacks. This vulnerability could pose a significant risk if not promptly addressed by system administrators. IBM has released a patch to mitigate the issue. It is strongly advised that users update their systems as soon as possible to prevent potential exploitation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- IBM Maximo Asset Management
Affected Vendors
- IBM