CVE-2025-2898

Published May 6, 2025

Last updated 10 months ago

Overview

Description
IBM Maximo Application Suite 9.0 could allow an attacker with some level of access to elevate their privileges due to a security configuration vulnerability in Role-Based Access Control (RBAC) configurations.
Source
psirt@us.ibm.com
NVD status
Analyzed
Products
maximo_application_suite

Risk scores

CVSS 3.1

Type
Primary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

psirt@us.ibm.com
CWE-266
nvd@nist.gov
NVD-CWE-noinfo

Social media

Hype score
Not currently trending

Configurations