Impact
The vulnerability in IBM Common Licensing Agent 9.0 and its ART counterpart allows an attacker to alter request parameters that are normally validated only on the client side. By modifying these values the attacker can submit inputs that the server accepts without further checks, resulting in unintended application behavior. This failure of proper server‑side input validation can lead to execution of actions that should be restricted or to data corruption, effectively undermining the integrity guarantees of the licensing system.
Affected Systems
IBM Common Licensing products, specifically the Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2, have been identified as vulnerable. Users operating these components should promptly assess whether they are running any of the listed versions.
Risk and Exploitability
The CVSS score of 6.2 indicates moderate severity, while the EPSS score is not available, making it difficult to gauge the current probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation at the time of analysis. Attackers would need the ability to send crafted requests to the affected server, which implies a remote or network‑based attack vector. Successful exploitation would allow submission of unauthorized values, potentially altering licensing data or authority controls, thereby affecting confidentiality, integrity, and availability of the licensing infrastructure.
OpenCVE Enrichment