Impact
IBM Common Licensing Agent and ART components generate error messages that embed details about the system environment, user identities, or related data. When an error condition arises, the unfiltered message is written to logs or presented to the user, exposing sensitive context that could facilitate further exploitation such as credential harvesting or privilege escalation. The weakness is rooted in inadequate sanitization of error output, consistent with a content disclosure flaw.
Affected Systems
The affected software includes IBM Common Licensing Agent versions 9.0, 9.0.0.1, and 9.0.0.2 along with the ART modules 9.0, 9.0.0.1, and 9.0.0.2. All run as part of the IBM Common Licensing suite. Users should upgrade to IBM Common Licensing 9.1, which removes the vulnerable error‑handling logic.
Risk and Exploitability
The CVSS score of 4.3 indicates a low‑to‑moderate severity. The EPSS score of less than 1% suggests a very low likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The likely attack path involves triggering an error through malformed requests or configuration faults and then accessing the unfiltered message from logs or the user interface. If log files are readable by external actors, the exposure is amplified, although the impact remains limited to disclosure of sensitive data and does not directly enable code execution or denial of service.
OpenCVE Enrichment