{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aibmcommon_licensing_agent9.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ibm:common_licensing_agent:9.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:common_licensing_agent:9.0.0.1:*:*:*:*:*:*:*","cpe:2.3:a:ibm:common_licensing_agent:9.0.0.2:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":10,"id":"CVE-2025-15399"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Common Licensing Agent (9.0, 9.0.0.1, 9.0.0.2)","Common Licensing ART (9.0, 9.0.0.1, 9.0.0.2)"],"_cs_severities":["medium"],"_cs_tags":["vulnerability","web-security","cve"],"_cs_type":"advisory","_cs_vendors":["IBM"],"content_html":"\u003cp\u003eIBM Common Licensing Agent and ART (versions 9.0, 9.0.0.1, and 9.0.0.2) are vulnerable to a cross-site request forgery (CSRF) vulnerability, tracked as CVE-2025-15399. This vulnerability allows an unauthenticated attacker to induce an authenticated user to perform unwanted or unauthorized actions within the web application. Given the critical CVSS v3.1 base score of 10.0, the impact of this flaw is significant, as it may permit attackers to execute arbitrary operations as the victim user. If the victim holds administrative privileges, this can lead to full system compromise. Defenders should prioritize auditing the implementation of anti-CSRF tokens and session management within these specific IBM components to prevent exploitation.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an attacker to execute unauthorized actions on behalf of an authenticated user. This could result in unauthorized administrative modifications, configuration changes, or access to sensitive licensing data. Given the 10.0 CVSS score, the potential for widespread impact on affected infrastructure is high, specifically within environments managing IBM licensing via these affected agents.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize checking if IBM Common Licensing Agent or ART is deployed in the environment and determine if they are running version 9.0, 9.0.0.1, or 9.0.0.2. Consult IBM support channels or official security bulletins to identify available patches or mitigation strategies for CVE-2025-15399. Ensure web application firewalls (WAF) are configured to inspect incoming requests for anomalous patterns, although CSRF flaws are typically remediated at the application code level via anti-CSRF token implementation.\u003c/p\u003e\n","date_modified":"2026-09-18T18:06:39Z","date_published":"2026-09-18T18:06:39Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2025-15399/","summary":"IBM Common Licensing Agent and ART versions 9.0 through 9.0.0.2 contain a cross-site request forgery (CSRF) vulnerability that enables unauthenticated attackers to perform unauthorized actions on behalf of an authenticated user.","title":"CSRF Vulnerability in IBM Common Licensing Agent and ART","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2025-15399/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:ibm:common_licensing_agent:9.0:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}