Impact
IBM Common Licensing Agent 9.0 and its ART counterpart perform input validation solely on the client side while the server does not enforce the same restrictions. An attacker that can modify request parameters is able to send values that the server accepts without further checks, leading to unintended application behavior. This flaw, classified as a client‑side input validation failure (CWE‑20), can allow the execution of actions that should be restricted and may corrupt licensing data.
Affected Systems
IBM Common Licensing products, specifically the Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2, are identified as vulnerable. These versions were released under the IBM:Common Licensing vendor and are available via the IBM Passport Advantage portal.
Risk and Exploitability
The CVSS score of 6.2 indicates moderate severity. The EPSS score is less than 1 %, suggesting a low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog, meaning no widespread exploitation is documented. Attackers would need the ability to send crafted requests to the affected servers, implying a remote or network‑based attack vector. Successful exploitation could result in unauthorized modification of licensing data or other system‑wide effects.
OpenCVE Enrichment