{"id":"CVE-2025-15399","published":"2026-09-18T16:17:02.387","lastModified":"2026-09-21T13:17:06.053","description":"IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.","cvssScore":10,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","cwes":["CWE-352"],"vendors":[],"products":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7286490","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows an attacker to execute unauthorized actions by tricking a user into performing a request on a website they trust, potentially leading to data theft, system compromise, and unauthorized access.","exploitability":"Exploitation is relatively easy as it requires an attacker to craft a malicious request that the user's browser will execute without their knowledge. Precondition is that the user is already logged into the affected website.","blast_radius":"If exploited, the impact could be severe, including data exfiltration, system compromise, and unauthorized access to sensitive information.","remediation":"Disable the affected Common Licensing Agent and ART features or upgrade to IBM Common Licensing Agent 9.0.0.3 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["csrf","web","auth-bypass","cross-site","licensing"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:55:03.010Z"}}