Home
MEDIUM: 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NDefault status
unaffected
9.2.0 (semver)
affected
Description
IBM License Metric Tool 9.2.0 through 9.2.40 could allow an authenticated user to bypass access controls in the REST API interface and perform unauthorized actions.
Problem types
CWE-284 Authentication Bypass Using an Alternate Path or Channel
Product status
9.2.0 (semver)
References
www.ibm.com/support/pages/node/7246534