Description
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Published: 2026-09-18
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting that can lead to credential disclosure
Action: Apply Patch
AI Analysis

Impact

IBM Common Licensing Agent and ART components, specifically versions 9.0, 9.0.0.1, and 9.0.0.2, contain a cross‑site scripting flaw. An unauthenticated attacker can inject arbitrary JavaScript into the web interface of the Administration Tool or Agent, thereby modifying page behavior. If executed within a trusted session, the injected scripts can steal session cookies or other sensitive data, potentially exposing credentials or enabling further compromise.

Affected Systems

The vulnerability affects IBM Common Licensing products delivered under the Common Licensing umbrella, specifically the Agent and ART modules across the 9.0 release line installed by organizations that use the License Key Server Administration and Reporting Tool or the LKS Administration Agent. Any environment running those components without the latest update is susceptible.

Risk and Exploitability

The CVSS score of 6.1 indicates moderate severity. The EPSS score of < 1% indicates a very low likelihood of exploitation. The vulnerability is not listed in CISA's KEV catalog, suggesting no known widespread exploitation yet. Based on the description, the likely attack vector is through the web UI accessed by an unauthenticated user; an attacker would need to reach the web interface and supply malicious input to trigger the script execution.

Generated by OpenCVE AI on September 19, 2026 at 18:21 UTC.

Remediation

Vendor Solution

Download and install IBM Common Licensing 9.1 from Passport Advantage https://www.ibm.com/software/passportadvantage/pao-customer Users are strongly advised to update to the latest version (IBM Common Licensing 9.1) to mitigate any potential risks associated with these vulnerabilities.


OpenCVE Recommended Actions

  • Download and install IBM Common Licensing 9.1 from Passport Advantage for all affected Agent and ART instances
  • Restart the IBM Common Licensing services to apply the new version
  • During maintenance, restrict external access to the web interface using firewall or access‑control lists until the update is complete

Generated by OpenCVE AI on September 19, 2026 at 18:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Title Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent
First Time appeared Ibm
Ibm common Licensing
Weaknesses CWE-79
CPEs cpe:2.3:a:ibm:common_licensing:agent:*:*:*:*:*:*:*
cpe:2.3:a:ibm:common_licensing:art:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm common Licensing
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Ibm Common Licensing
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-18T16:17:38.648Z

Reserved: 2026-01-16T14:47:22.104Z

Link: CVE-2026-1037

cve-icon Vulnrichment

Updated: 2026-09-18T16:16:45.591Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T16:17:06.533

Modified: 2026-09-18T18:17:47.257

Link: CVE-2026-1037

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:15:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')