PT-2025-39829 · Ibm · Ibm License Metric Tool

Published

2025-09-29

·

Updated

2025-09-29

·

CVE-2025-36351

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions IBM License Metric Tool versions 9.2.0 through 9.2.40
Description An authenticated user can bypass access controls within the REST API interface, potentially leading to unauthorized actions. The issue relates to access control within the REST API. The API endpoint allows bypassing of intended security measures.
Recommendations Update to a version later than 9.2.40.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2025-16245
CVE-2025-36351

Affected Products

Ibm License Metric Tool