OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2025-15399

CRITICAL · CVSS 10 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-09-18 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

IBM Common Licensing Agent and associated versions are critically vulnerable to cross-site request forgery, enabling attackers to perform unauthorized actions on behalf of trusted users. This vulnerability poses a severe risk to any organization utilizing these products, as it could lead to significant data breaches or system compromises. Organizations using these versions should prioritize immediate remediation to mitigate potential exploitation.

CVE
CVE-2025-15399
Severity
CRITICAL
CVSS
10
EPSS
0.18%

Original NVD Description

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.