IBM License Metric Tool 9.2.0 through 9.2.40

could allow an authenticated user to bypass access controls in the REST API interface and perform unauthorized actions.
Fixes

Solution

For all affected versions, IBM strongly recommends addressing the vulnerability now by upgrading to the latest ILMT Server version 9.2.41 or later using the following procedure: https://www.ibm.com/docs/en/license-metric-tool?topic=tool-upgrading-latest-version


Workaround

No workaround given by the vendor.

History

Mon, 29 Sep 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 29 Sep 2025 14:45:00 +0000

Type Values Removed Values Added
Description IBM License Metric Tool 9.2.0 through 9.2.40 could allow an authenticated user to bypass access controls in the REST API interface and perform unauthorized actions.
Title IBM License Metric Tool bypass security
First Time appeared Ibm
Ibm license Metric Tool
Weaknesses CWE-284
CPEs cpe:2.3:a:ibm:license_metric_tool:9.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:license_metric_tool:9.2.40:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm license Metric Tool
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2025-09-29T15:04:12.822Z

Reserved: 2025-04-15T21:16:54.209Z

Link: CVE-2025-36351

cve-icon Vulnrichment

Updated: 2025-09-29T15:04:03.826Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2025-09-29T15:16:08.173

Modified: 2025-09-29T19:34:10.030

Link: CVE-2025-36351

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.