Description
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Published: 2026-09-18
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting that may lead to credential disclosure
Action: Patch Immediately
AI Analysis

Impact

IBM Common Licensing Agent and ART components are vulnerable to reflected or stored cross‑site scripting. An attacker who can reach the web interface without authentication may inject arbitrary JavaScript that executes in the browser of a legitimate user. The injected code can alter page content, capture form input or session cookies, and thereby facilitate credential theft or other data exfiltration. The flaw does not provide native remote code execution or direct privilege escalation on the host, but it can compromise the confidentiality of user credentials and the integrity of web‑based management operations.

Affected Systems

The affected products are IBM Common Licensing Agent 9.0, 9.0.0.1 and 9.0.0.2, and IBM Common Licensing ART 9.0, 9.0.0.1 and 9.0.0.2. These components are part of the IBM License Key Server Administration and Reporting Tool suite and are typically deployed on enterprise servers with an exposed web UI used by administrators.

Risk and Exploitability

The CVSS score of 6.1 indicates moderate severity. The EPSS score is below 1 % and the vulnerability is not listed in CISA’s KEV catalog, implying limited or no active exploitation. The likely attack vector is remote, via the publicly reachable web UI, and requires no authentication, making the opportunity to exploit wide. Because the flaw permits execution of user‑supplied script in the context of the web browser, an attacker could hijack sessions or leak credentials if a legitimate user is tricked into visiting a crafted page.

Generated by OpenCVE AI on September 19, 2026 at 17:58 UTC.

Remediation

Vendor Solution

Download and install IBM Common Licensing 9.1 from Passport Advantage https://www.ibm.com/software/passportadvantage/pao-customer Users are strongly advised to update to the latest version (IBM Common Licensing 9.1) to mitigate any potential risks associated with these vulnerabilities.


OpenCVE Recommended Actions

  • Download and install IBM Common Licensing 9.1 from Passport Advantage, then restart the Common Licensing Agent and ART services to activate the patch
  • If an immediate patch is impossible, block external access to the vulnerable web UI or place the hosts behind a restrictive firewall so that only authorized personnel can reach the interface
  • Enable role‑based access controls on the web UI, ensuring that only authenticated administrators can access the interface

Generated by OpenCVE AI on September 19, 2026 at 17:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Title Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent
First Time appeared Ibm
Ibm common Licensing
Weaknesses CWE-79
CPEs cpe:2.3:a:ibm:common_licensing:agent:*:*:*:*:*:*:*
cpe:2.3:a:ibm:common_licensing:art:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm common Licensing
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Ibm Common Licensing
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-19T14:11:44.429Z

Reserved: 2026-01-16T02:46:40.811Z

Link: CVE-2026-1031

cve-icon Vulnrichment

Updated: 2026-09-19T14:11:26.956Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T16:17:06.410

Modified: 2026-09-19T15:16:59.273

Link: CVE-2026-1031

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T18:00:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')