Impact
Based on the description, this vulnerability is a client‑side cross‑site scripting flaw that permits an attacker to inject arbitrary JavaScript code into the Web UI of IBM Common Licensing Agent and Administration Tool. The injected script runs with the privileges of an authenticated user, potentially revealing session cookies, credentials, or other sensitive data. The impact is limited to credential exposure and session hijacking within a trusted session, as the user must be logged in or tricked into loading a malicious page.
Affected Systems
All versions of IBM Common Licensing Agent 9.0, including Agent 9.0.0.1 and Agent 9.0.0.2, and IBM Common Licensing Administration Tool 9.0, including ART 9.0.0.1 and ART 9.0.0.2, are affected. Upgrading to IBM Common Licensing 9.1 removes the flaw.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. The EPSS score is less than 1% and the vulnerability is not listed in CISA KEV, suggesting current exploitation risk is low. However, the likely attack vector is the web interface where user input is reflected. Based on the description, it is inferred that an attacker can supply malicious input through the UI, which is then rendered without proper escaping. An attacker with web access or the ability to trick an authenticated user into visiting a crafted page can exploit the vulnerability. Mitigating the risk requires applying the vendor patch, restricting UI access, and implementing input validation or a WAF.
OpenCVE Enrichment