Description
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Published: 2026-09-18
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑site scripting that can lead to credentials disclosure within a trusted session
Action: Patch
AI Analysis

Impact

The vulnerability is a cross‑site scripting flaw in IBM Common Licensing Agent and ART 9.0 series, enabling an attacker to embed arbitrary JavaScript in the Web UI. If executed, the script can modify UI behavior and potentially read or exfiltrate credentials that a user has already authenticated, thereby enabling credential disclosure within a trusted session.

Affected Systems

Affected products include IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2, all part of the IBM Common Licensing suite. All versions prior to 9.1 are vulnerable; IBM recommends upgrading to IBM Common Licensing 9.1.

Risk and Exploitability

The flaw carries a CVSS base score of 6.1, indicating medium severity. The EPSS score indicates a very low exploitation probability (<1%). The lack of inclusion in the CISA KEV catalog means no publicly confirmed exploits yet. The most likely attack vector is an attacker who can influence input seen by the web UI, such as a malicious user or an attacker able to trick a portal user into loading a crafted page. Exploitation would not require elevated privileges beyond what the attacker can obtain via the UI and can lead to theft of user credentials within the session.

Generated by OpenCVE AI on September 19, 2026 at 17:20 UTC.

Remediation

Vendor Solution

Download and install IBM Common Licensing 9.1 from Passport Advantage Users are strongly advised to update to the latest version (IBM Common Licensing 9.1) to mitigate any potential risks associated with these vulnerabilities.


OpenCVE Recommended Actions

  • Download and install IBM Common Licensing 9.1 from Passport Advantage to replace all vulnerable Agent and ART components
  • Re‑configure the web interface to enforce authentication and limit exposure to trusted internal users only, using firewall or network segmentation if an immediate upgrade is not possible
  • Validate that all user‑supplied content is properly encoded before rendering in any web page to prevent script execution

Generated by OpenCVE AI on September 19, 2026 at 17:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Title Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent
First Time appeared Ibm
Ibm common Licensing
Weaknesses CWE-79
CPEs cpe:2.3:a:ibm:common_licensing:agent:*:*:*:*:*:*:*
cpe:2.3:a:ibm:common_licensing:art:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm common Licensing
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Ibm Common Licensing
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-19T14:21:50.334Z

Reserved: 2026-01-16T02:12:59.015Z

Link: CVE-2026-1025

cve-icon Vulnrichment

Updated: 2026-09-19T14:11:51.451Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T16:17:06.030

Modified: 2026-09-19T15:16:59.057

Link: CVE-2026-1025

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T17:30:07Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')