Impact
IBM Common Licensing Agent and ART components are vulnerable to reflected or stored cross‑site scripting. An attacker who can reach the web interface without authentication may inject arbitrary JavaScript that executes in the browser of a legitimate user. The injected code can alter page content, capture form input or session cookies, and thereby facilitate credential theft or other data exfiltration. The flaw does not provide native remote code execution or direct privilege escalation on the host, but it can compromise the confidentiality of user credentials and the integrity of web‑based management operations.
Affected Systems
The affected products are IBM Common Licensing Agent 9.0, 9.0.0.1 and 9.0.0.2, and IBM Common Licensing ART 9.0, 9.0.0.1 and 9.0.0.2. These components are part of the IBM License Key Server Administration and Reporting Tool suite and are typically deployed on enterprise servers with an exposed web UI used by administrators.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity. The EPSS score is below 1 % and the vulnerability is not listed in CISA’s KEV catalog, implying limited or no active exploitation. The likely attack vector is remote, via the publicly reachable web UI, and requires no authentication, making the opportunity to exploit wide. Because the flaw permits execution of user‑supplied script in the context of the web browser, an attacker could hijack sessions or leak credentials if a legitimate user is tricked into visiting a crafted page.
OpenCVE Enrichment