4.3

CVE-2025-36351

IBM License Metric Tool bypass security

IBM License Metric Tool 9.2.0 through 9.2.40 

could allow an authenticated user to bypass access controls in the REST API interface and perform unauthorized actions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IbmLicense Metric Tool Version >= 9.2.0 < 9.2.41
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.04% 0.106
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
psirt@us.ibm.com 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.