Impact
IBM Common Licensing Agent and ART modules are vulnerable to a cross‑site request forgery flaw. The flaw permits an attacker who tricks a trusted user into submitting a forged request to the web interface to carry out actions that the victim’s account would normally allow. Because the flaw operates through a web endpoint that requires authentication, the attacker can execute operations on the server without needing local or privileged access.
Affected Systems
Affected releases are IBM Common Licensing Agent versions 9.0, 9.0.0.1 and 9.0.0.2 and ART 9.0, 9.0.0.1 and 9.0.0.2. All of those components are distributed under the IBM Common Licensing umbrella. The vendor recommendation is to upgrade to IBM Common Licensing 9.1, which contains the fix.
Risk and Exploitability
The CVSS score of 10 classifies the vulnerability as critical. EPSS is listed as <1%, indicating a very low predicted exploitation probability, and the issue is not currently in the CISA KEV catalog. The attack path requires the victim to be authenticated against the web interface; an attacker can then lure the victim to click a malicious link or load a page that sends a forged request. Because the vulnerability does not need direct server access, exploiting it can be performed remotely from a web browser, but a malicious request must target a system where the victim is logged in.
OpenCVE Enrichment