MEDIUM🇵🇱 Wersja polska

CVE-2025-36352

CVSS 6.4v3.1pub. 2025-09-29upd. 2025-10-03

IBM License Metric Tool 9.2.0 through 9.2.40 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
  • IBM License Metric Tool

    APP
    Ibm
    < 9.2.41
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2016-8964CRITICAL9.8PL ✓same product

IBM BigFix Inventory: niewystarczające blokowanie konta umożliwia atak brute force

CVE-2016-8980HIGH8.1same product

IBM BigFix Inventory v9 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE)...

CVE-2025-36351MEDIUM4.3same product

IBM License Metric Tool 9.2.0 through 9.2.40 could allow an authenticated user to bypass access controls in ...

CVE-2023-43044MEDIUM5.3same product

IBM License Metric Tool 9.2 could allow a remote attacker to traverse directories on the system. An attacker c...

CVE-2016-8961MEDIUM6.1same product

IBM BigFix Inventory v9 could allow a remote attacker to conduct phishing attacks, using an open redirect atta...