Loading vulnerability details…
CVSS v3.1
4.3
EPSS
0.22%
Published
Sep 29, 2025
Modified
Oct 3, 2025
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
IBM License Metric Tool 9.2.0 through 9.2.40 could allow an authenticated user to bypass access controls in the REST API interface and perform unauthorized actions.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NWeaknesses (CWE)
Affected Products (1)
References (1)