Impact
IBM Common Licensing Agent and ART components, specifically versions 9.0, 9.0.0.1, and 9.0.0.2, contain a cross‑site scripting flaw. An unauthenticated attacker can inject arbitrary JavaScript into the web interface of the Administration Tool or Agent, thereby modifying page behavior. If executed within a trusted session, the injected scripts can steal session cookies or other sensitive data, potentially exposing credentials or enabling further compromise.
Affected Systems
The vulnerability affects IBM Common Licensing products delivered under the Common Licensing umbrella, specifically the Agent and ART modules across the 9.0 release line installed by organizations that use the License Key Server Administration and Reporting Tool or the LKS Administration Agent. Any environment running those components without the latest update is susceptible.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity. The EPSS score of < 1% indicates a very low likelihood of exploitation. The vulnerability is not listed in CISA's KEV catalog, suggesting no known widespread exploitation yet. Based on the description, the likely attack vector is through the web UI accessed by an unauthenticated user; an attacker would need to reach the web interface and supply malicious input to trigger the script execution.
OpenCVE Enrichment