Product
ibm license metric tool
18 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-36352
CVE-2025-36351
CVE-2023-43044
CVE-2016-8964
CVE-2016-8977
CVE-2016-8963
CVE-2016-8967
CVE-2016-8981
CVE-2016-8980
CVE-2016-8966
CVE-2016-8961
CVE-2015-4929
CVE-2014-8927
CVE-2014-8926
CVE-2014-4778
CVE-2014-4774
CVE-2014-8924
CVE-2014-4776
< 9.2.41
IBM License Metric Tool 9.2.0 through 9.2.40 is vulnerable to stored cross-site scripting. This vulnerability allows an authentica
>= 9.2.0 and < 9.2.41
IBM License Metric Tool 9.2.0 through 9.2.40 could allow an authenticated user to bypass access controls in the REST API interfa
< 9.2.33
IBM License Metric Tool 9.2 could allow a remote attacker to traverse directories on the system. An attacker could send a speciall
>= 9.0 and < 9.2.8
IBM BigFix Inventory v9 9.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account c
all versions
IBM BigFix Inventory v9 could disclose sensitive information to an unauthorized user using HTTP GET requests. This information cou
all versions
IBM BigFix Inventory v9 stores potentially sensitive information in log files that could be read by a local user.
all versions
IBM BigFix Inventory v9 9.2 stores user credentials in plain in clear text which can be read by a local user.
all versions
IBM BigFix Inventory v9 allows web pages to be stored locally which can be read by another user on the system.
all versions
IBM BigFix Inventory v9 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processi
all versions
IBM BigFix Inventory v9 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HT
all versions
IBM BigFix Inventory v9 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a
all versions
IBM License Metric Tool 9 before 9.2.1.0 and Endpoint Manager for Software Use Analysis 9 before 9.2.1.0 allow remote authenticate
all versions
Common Inventory Technology (CIT) before 2.7.0.2050 in IBM License Metric Tool 7.2.2, 7.5, and 9; Endpoint Manger for Software Use
all versions
Common Inventory Technology (CIT) before 2.7.0.2050 in IBM License Metric Tool 7.2.2, 7.5, and 9; Endpoint Manger for Software Use
all versions
IBM License Metric Tool 9 before 9.1.0.2 and Endpoint Manager for Software Use Analysis 9 before 9.1.0.2 do not send an X-Frame-Op
all versions
Cross-site request forgery (CSRF) vulnerability in the login page in IBM License Metric Tool 9 before 9.1.0.2 and Endpoint Manager
all versions
The server in IBM License Metric Tool 7.2.2 before IF15 and 7.5 before IF24 and Tivoli Asset Discovery for Distributed 7.2.2 befor
all versions
IBM License Metric Tool 9 before 9.1.0.2 does not have an off autocomplete attribute for authentication fields, which makes it eas