CVE-2025-15399: IBM Common Licensing vulnerability
Published Sep 7, 2026
·Updated
IBM Common Licensing is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
Affected Software
6 affected components
IBM Common Licensing<=Agent 9.0
IBM Common Licensing<=Agent 9.0.0.1
IBM Common Licensing<=Agent 9.0.0.2
IBM Common Licensing<=ART 9.0
IBM Common Licensing<=ART 9.0.0.1
IBM Common Licensing<=ART 9.0.0.2
Event History
Sep 7, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
The attacker would need to cause a user trusted by the IBM Common Licensing website to submit a malicious request. The vulnerability involves cross-site request forgery, so exploitation relies on actions being transmitted in the context of that trusted user.
2
What could exploitation allow?
Successful exploitation could allow malicious and unauthorized actions to be executed through requests transmitted from a user the website trusts.