license_metric_tool vulnerabilities
CVEs whose affected-version data names the license_metric_tool package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2025-36352Medium· 6.4IBM License Metric Tool 9.2.0 through 9.2.40 is vulnerable to stored cross-site scripting
IBM License Metric Tool 9.2.0 through 9.2.40 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentia…
▾ Sunlitibm · license_metric_toolEPSS 0.18%via NVD
CVE-2025-36351Medium· 4.3IBM License Metric Tool 9.2.0 through 9.2.40 could allow an authenticated user to bypass access controls in the REST API interface and perform unauthorized actions.
IBM License Metric Tool 9.2.0 through 9.2.40 could allow an authenticated user to bypass access controls in the REST API interface and perform unauthorized actions.
▾ Sunlitibm · license_metric_toolEPSS 0.24%via NVD