Changeflow GovPing Data Privacy & Cybersecurity IBM License Metric Tool Vulnerabilities
Priority review Notice Added Final

IBM License Metric Tool Vulnerabilities

Favicon for wid.cert-bund.de CERT-Bund Security Advisories
Published March 25th, 2026
Detected March 26th, 2026
Email

Summary

CERT-Bund has issued a security advisory regarding multiple vulnerabilities in IBM License Metric Tool versions prior to 9.2.43. The vulnerabilities, with a CVSS base score of 7.5, could allow remote attackers to disclose information, perform cross-site scripting attacks, or cause a denial of service. Mitigation is available.

What changed

CERT-Bund has published a security advisory (WID-SEC-2026-0881) detailing multiple vulnerabilities affecting IBM License Metric Tool versions earlier than 9.2.43. The advisory notes a CVSS base score of 7.5, indicating a high severity, and a temporal score of 6.5. These vulnerabilities can be exploited remotely to disclose information, execute cross-site scripting (XSS) attacks, or cause a denial of service (DoS).

Organizations utilizing IBM License Metric Tool should immediately review their installed versions and apply available mitigations. The advisory indicates that affected operating systems include Linux, UNIX, and Windows. Affected product versions are IBM License Metric Tool <9.2.43. Prompt action is recommended to address these security risks and prevent potential exploitation.

What to do next

  1. Review installed version of IBM License Metric Tool
  2. Apply available mitigations for versions prior to 9.2.43

Source document (simplified)

[WID-SEC-2026-0881] IBM License Metric Tool: Mehrere Schwachstellen CVSS Base Score 7.5 (hoch) CVSS Temporal Score 6.5 (mittel) Remoteangriff ja Datum 25.03.2026 Stand 26.03.2026 Mitigation ja

Betroffene Systeme

Betriebssystem

  • Linux
  • Sonstiges
  • UNIX
  • Windows

Produktbeschreibung

Das IBM License Metric Tool dient der Lizenzverwaltung für IBM Produkte.

Produkte

25.03.2026
- IBM License Metric Tool <9.2.43

Angriff

Angriff

Ein Angreifer kann mehrere Schwachstellen in IBM License Metric Tool ausnutzen, um Informationen offenzulegen, einen Cross Site Scripting Angriff durchzuführen oder einen Denial of Service zu verursachen. CVE Informationen Versionshistorie Feedback zum Advisory geben

Source

Analysis generated by AI. Source diff and links are from the original.

Classification

Agency
CERT-Bund
Published
March 25th, 2026
Instrument
Notice
Legal weight
Non-binding
Stage
Final
Change scope
Substantive
Document ID
WID-SEC-2026-0881

Who this affects

Applies to
Manufacturers
Industry sector
3254 Pharmaceutical Manufacturing
Activity scope
Software Vulnerability Management License Management
Geographic scope
Germany DE

Taxonomy

Primary area
Cybersecurity
Operational domain
IT Security
Compliance frameworks
NIST CSF
Topics
Software Vulnerabilities IT Asset Management

Get Data Privacy & Cybersecurity alerts

Weekly digest. AI-summarized, no noise.

Free. Unsubscribe anytime.

Get alerts for this source

We'll email you when CERT-Bund Security Advisories publishes new changes.

Optional. Personalizes your daily digest.

Free. Unsubscribe anytime.