CVE-2025-36351: IBM License Metric Tool
Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.
IBM License Metric Tool 9.2.0 through 9.2.40 could allow an authenticated user to bypass access controls in the REST API interface and perform unauthorized actions.
Affected products
- IBM License Metric Tool: from 9.2.0, before 9.2.41 (fixed in 9.2.41)
Published 2025-09-29. Last modified 2026-10-09.