MEDIUM · 4.3

CVE-2025-36351

IBM License Metric Tool 9.2.0 through 9.2.40 could allow an authenticated user to bypass access controls in the REST API interface and perform unauthorized actions.

Vulnerability Description

IBM License Metric Tool 9.2.0 through 9.2.40 could allow an authenticated user to bypass access controls in the REST API interface and perform unauthorized actions.

CVSS Score

4.3

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
IbmLicense Metric Tool>= 9.2.0, < 9.2.41

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-36351?

CVE-2025-36351 is a vulnerability with a CVSS score of 4.3 (MEDIUM). IBM License Metric Tool 9.2.0 through 9.2.40 could allow an authenticated user to bypass access controls in the REST API interface and perform unauthorized actions.

How severe is CVE-2025-36351?

CVE-2025-36351 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2025-36351?

Check the references section above for vendor advisories and patch information. Affected products include: Ibm License Metric Tool.