Skip to content
Threat Feed
medium advisory

CSRF Vulnerability in IBM Common Licensing Agent and ART

IBM Common Licensing Agent and ART versions 9.0 through 9.0.0.2 contain a cross-site request forgery (CSRF) vulnerability that enables unauthenticated attackers to perform unauthorized actions on behalf of an authenticated user.

CVE search metadata

CVE search record: CVE-2025-15399. Severity: critical. CVSS: 10.0. KEV: no. Product: Common Licensing Agent (9.0, 9.0.0.1, 9.0.0.2), Common Licensing ART (9.0, 9.0.0.1, 9.0.0.2). Brief: CSRF Vulnerability in IBM Common Licensing Agent and ART. Brief link: https://feed.craftedsignal.io/briefs/2026-09-cve-2025-15399/

IBM Common Licensing Agent and ART (versions 9.0, 9.0.0.1, and 9.0.0.2) are vulnerable to a cross-site request forgery (CSRF) vulnerability, tracked as CVE-2025-15399. This vulnerability allows an unauthenticated attacker to induce an authenticated user to perform unwanted or unauthorized actions within the web application. Given the critical CVSS v3.1 base score of 10.0, the impact of this flaw is significant, as it may permit attackers to execute arbitrary operations as the victim user. If the victim holds administrative privileges, this can lead to full system compromise. Defenders should prioritize auditing the implementation of anti-CSRF tokens and session management within these specific IBM components to prevent exploitation.

Impact

Successful exploitation of this vulnerability allows an attacker to execute unauthorized actions on behalf of an authenticated user. This could result in unauthorized administrative modifications, configuration changes, or access to sensitive licensing data. Given the 10.0 CVSS score, the potential for widespread impact on affected infrastructure is high, specifically within environments managing IBM licensing via these affected agents.

Recommendation

Prioritize checking if IBM Common Licensing Agent or ART is deployed in the environment and determine if they are running version 9.0, 9.0.0.1, or 9.0.0.2. Consult IBM support channels or official security bulletins to identify available patches or mitigation strategies for CVE-2025-15399. Ensure web application firewalls (WAF) are configured to inspect incoming requests for anomalous patterns, although CSRF flaws are typically remediated at the application code level via anti-CSRF token implementation.


Immediate actions

Inventory all instances of IBM Common Licensing Agent and ART to identify versions 9.0 through 9.0.0.2.

IT Operations 48h

Mitigations

Monitor for official IBM patches and apply them to all identified vulnerable agents.

immediate IT Operations

CVE-2025-15399