CVE-2025-15399
10.0IBM · Common Licensing
IBM Common Licensing is vulnerable to a cross-site request forgery (CSRF) flaw, potentially allowing unauthorized actions to be performed by a trusted user.
Executive summary
IBM Common Licensing versions 9.0 and 9.0.0.x are affected by a critical cross-site request forgery vulnerability that permits unauthorized administrative actions.
Vulnerability
The application is susceptible to a Cross-Site Request Forgery (CWE-352) attack, which allows an unauthenticated attacker to force a victim into executing unauthorized operations within the context of their session.
Business impact
Successful exploitation allows an attacker to perform unauthorized actions with the privileges of a logged-in user, which could result in full system compromise given the CVSS score of 10.0. This represents a significant risk to data integrity and service availability, as the vulnerability is remotely exploitable without requiring authentication.
Remediation
Immediate Action: Upgrade immediately to IBM Common Licensing version 9.1 as specified in the vendor security advisory.
Proactive Monitoring: Review web server and application access logs for suspicious requests or unexpected state-changing actions originating from external sources.
Compensating Controls: Implement a Web Application Firewall (WAF) to detect and block malicious requests that lack proper anti-CSRF tokens or originate from untrusted cross-origin sources.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the critical severity score and the potential for full system compromise, organizations should prioritize the deployment of IBM Common Licensing version 9.1. Ensure all affected agents and runtime components are updated to the latest version to eliminate this exposure.
More IBM CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section