IBM License Metric Tool 9.2.0 through 9.2.40 could allow an authenticated user to bypass access controls in the REST API interface and perform unauthorized actions.
History

Fri, 03 Oct 2025 18:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:license_metric_tool:*:*:*:*:*:*:*:*

Mon, 29 Sep 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 29 Sep 2025 14:45:00 +0000

Type Values Removed Values Added
Description IBM License Metric Tool 9.2.0 through 9.2.40 could allow an authenticated user to bypass access controls in the REST API interface and perform unauthorized actions.
Title IBM License Metric Tool bypass security
First Time appeared Ibm
Ibm license Metric Tool
Weaknesses CWE-284
CPEs cpe:2.3:a:ibm:license_metric_tool:9.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:license_metric_tool:9.2.40:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm license Metric Tool
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2025-09-29T15:04:12.822Z

Reserved: 2025-04-15T21:16:54.209Z

Link: CVE-2025-36351

cve-icon Vulnrichment

Updated: 2025-09-29T15:04:03.826Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-29T15:16:08.173

Modified: 2025-10-03T17:53:55.820

Link: CVE-2025-36351

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.