{"id":"CVE-2025-15399","title":"IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from …","summary":"IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from …","severity":"critical","cvss":10,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","cwe":["CWE-352"],"vendor":"IBM","product":"Common Licensing","affected":["common_licensing Agent 9.0","common_licensing Agent 9.0.0.1","common_licensing Agent 9.0.0.2","common_licensing ART 9.0","common_licensing ART 9.0.0.1","common_licensing ART 9.0.0.2"],"published":"2026-09-18","updated":"2026-09-21","sourceUpdated":"2026-09-21T13:17:06.053","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-15399","references":[{"url":"https://www.ibm.com/support/pages/node/7286490","label":"psirt@us.ibm.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"total","timestamp":"2026-09-19T03:56:41.992763Z"},"epss":0.00253,"epssPercentile":0.1708,"ingestedAt":"2026-09-18T16:45:41.375Z","slug":"CVE-2025-15399","body":"## Overview\n\nIBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":55,"depthScoreParts":{"impact":55,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}