No analysis available yet.
Vendor Solution
For all affected versions, IBM strongly recommends addressing the vulnerability now by upgrading to the latest ILMT Server version 9.2.41 or later using the following procedure: https://www.ibm.com/docs/en/license-metric-tool?topic=tool-upgrading-latest-version
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-31577 | IBM License Metric Tool 9.2.0 through 9.2.40 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. |
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7246534 |
|
Fri, 03 Oct 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:ibm:license_metric_tool:*:*:*:*:*:*:*:* |
Mon, 29 Sep 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 29 Sep 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM License Metric Tool 9.2.0 through 9.2.40 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Title | IBM License Metric Tool cross-site scripting | |
| First Time appeared |
Ibm
Ibm license Metric Tool |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:ibm:license_metric_tool:9.2.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:license_metric_tool:9.2.40:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm license Metric Tool |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-09-29T15:08:36.763Z
Reserved: 2025-04-15T21:16:54.209Z
Link: CVE-2025-36352
Updated: 2025-09-29T15:08:33.224Z
Status : Analyzed
Published: 2025-09-29T15:16:08.367
Modified: 2025-10-03T17:54:10.850
Link: CVE-2025-36352
No data.
OpenCVE Enrichment
No data.
EUVD