CVE-2014-4776: IBM License Metric Tool

Low severity, CVSS 2.1. EPSS: 0.7% chance of exploitation in the next 30 days.

IBM License Metric Tool 9 before 9.1.0.2 does not have an off autocomplete attribute for authentication fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.

Affected products

  • IBM License Metric Tool: version 9.0 only; version 9.0.1 only; version 9.1.0.1 only

Published 2015-05-20. Last modified 2026-06-17.