could allow an authenticated user to bypass access controls in the REST API interface and perform unauthorized actions.
No analysis available yet.
Vendor Solution
For all affected versions, IBM strongly recommends addressing the vulnerability now by upgrading to the latest ILMT Server version 9.2.41 or later using the following procedure: https://www.ibm.com/docs/en/license-metric-tool?topic=tool-upgrading-latest-version
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-31574 | IBM License Metric Tool 9.2.0 through 9.2.40 could allow an authenticated user to bypass access controls in the REST API interface and perform unauthorized actions. |
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7246534 |
|
Fri, 03 Oct 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:ibm:license_metric_tool:*:*:*:*:*:*:*:* |
Mon, 29 Sep 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 29 Sep 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM License Metric Tool 9.2.0 through 9.2.40 could allow an authenticated user to bypass access controls in the REST API interface and perform unauthorized actions. | |
| Title | IBM License Metric Tool bypass security | |
| First Time appeared |
Ibm
Ibm license Metric Tool |
|
| Weaknesses | CWE-284 | |
| CPEs | cpe:2.3:a:ibm:license_metric_tool:9.2.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:license_metric_tool:9.2.40:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm license Metric Tool |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-09-29T15:04:12.822Z
Reserved: 2025-04-15T21:16:54.209Z
Link: CVE-2025-36351
Updated: 2025-09-29T15:04:03.826Z
Status : Analyzed
Published: 2025-09-29T15:16:08.173
Modified: 2025-10-03T17:53:55.820
Link: CVE-2025-36351
No data.
OpenCVE Enrichment
No data.
EUVD