CVE-2025-15399

10.0

IBM · Common Licensing

IBM Common Licensing is vulnerable to a cross-site request forgery (CSRF) flaw, potentially allowing unauthorized actions to be performed by a trusted user.

Executive summary

IBM Common Licensing versions 9.0 and 9.0.0.x are affected by a critical cross-site request forgery vulnerability that permits unauthorized administrative actions.

Vulnerability

The application is susceptible to a Cross-Site Request Forgery (CWE-352) attack, which allows an unauthenticated attacker to force a victim into executing unauthorized operations within the context of their session.

Business impact

Successful exploitation allows an attacker to perform unauthorized actions with the privileges of a logged-in user, which could result in full system compromise given the CVSS score of 10.0. This represents a significant risk to data integrity and service availability, as the vulnerability is remotely exploitable without requiring authentication.

Remediation

Immediate Action: Upgrade immediately to IBM Common Licensing version 9.1 as specified in the vendor security advisory.

Proactive Monitoring: Review web server and application access logs for suspicious requests or unexpected state-changing actions originating from external sources.

Compensating Controls: Implement a Web Application Firewall (WAF) to detect and block malicious requests that lack proper anti-CSRF tokens or originate from untrusted cross-origin sources.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical severity score and the potential for full system compromise, organizations should prioritize the deployment of IBM Common Licensing version 9.1. Ensure all affected agents and runtime components are updated to the latest version to eliminate this exposure.

More IBM CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources