Description
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Published: 2026-09-18
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑site scripting enabling credential disclosure within trusted sessions.
Action: Apply Patch
AI Analysis

Impact

Based on the description, this vulnerability is a client‑side cross‑site scripting flaw that permits an attacker to inject arbitrary JavaScript code into the Web UI of IBM Common Licensing Agent and Administration Tool. The injected script runs with the privileges of an authenticated user, potentially revealing session cookies, credentials, or other sensitive data. The impact is limited to credential exposure and session hijacking within a trusted session, as the user must be logged in or tricked into loading a malicious page.

Affected Systems

All versions of IBM Common Licensing Agent 9.0, including Agent 9.0.0.1 and Agent 9.0.0.2, and IBM Common Licensing Administration Tool 9.0, including ART 9.0.0.1 and ART 9.0.0.2, are affected. Upgrading to IBM Common Licensing 9.1 removes the flaw.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity. The EPSS score is less than 1% and the vulnerability is not listed in CISA KEV, suggesting current exploitation risk is low. However, the likely attack vector is the web interface where user input is reflected. Based on the description, it is inferred that an attacker can supply malicious input through the UI, which is then rendered without proper escaping. An attacker with web access or the ability to trick an authenticated user into visiting a crafted page can exploit the vulnerability. Mitigating the risk requires applying the vendor patch, restricting UI access, and implementing input validation or a WAF.

Generated by OpenCVE AI on September 19, 2026 at 18:00 UTC.

Remediation

Vendor Solution

Download and install IBM Common Licensing 9.1 from Passport Advantage https://www.ibm.com/software/passportadvantage/pao-customer Users are strongly advised to update to the latest version (IBM Common Licensing 9.1) to mitigate any potential risks associated with these vulnerabilities.


OpenCVE Recommended Actions

  • Download and install IBM Common Licensing 9.1 from Passport Advantage to eliminate the flaw.
  • Restrict access to the IBM Common Licensing Web UI to authorized networks only, using firewall rules or VPN.
  • Deploy a web application firewall or implement input validation to block injected JavaScript payloads.
  • Monitor web interface logs for suspicious script injections and review session activity for signs of hijacking.

Generated by OpenCVE AI on September 19, 2026 at 18:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Title Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent
First Time appeared Ibm
Ibm common Licensing
Weaknesses CWE-79
CPEs cpe:2.3:a:ibm:common_licensing:agent:*:*:*:*:*:*:*
cpe:2.3:a:ibm:common_licensing:art:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm common Licensing
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Ibm Common Licensing
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-18T17:32:50.910Z

Reserved: 2026-01-16T02:36:27.399Z

Link: CVE-2026-1029

cve-icon Vulnrichment

Updated: 2026-09-18T17:32:43.437Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T16:17:06.157

Modified: 2026-09-18T18:17:47.257

Link: CVE-2026-1029

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T18:15:02Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')