Impact
The vulnerability is a cross‑site scripting flaw in IBM Common Licensing Agent and ART 9.0 series, enabling an attacker to embed arbitrary JavaScript in the Web UI. If executed, the script can modify UI behavior and potentially read or exfiltrate credentials that a user has already authenticated, thereby enabling credential disclosure within a trusted session.
Affected Systems
Affected products include IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2, all part of the IBM Common Licensing suite. All versions prior to 9.1 are vulnerable; IBM recommends upgrading to IBM Common Licensing 9.1.
Risk and Exploitability
The flaw carries a CVSS base score of 6.1, indicating medium severity. The EPSS score indicates a very low exploitation probability (<1%). The lack of inclusion in the CISA KEV catalog means no publicly confirmed exploits yet. The most likely attack vector is an attacker who can influence input seen by the web UI, such as a malicious user or an attacker able to trick a portal user into loading a crafted page. Exploitation would not require elevated privileges beyond what the attacker can obtain via the UI and can lead to theft of user credentials within the session.
OpenCVE Enrichment