Impact
The vulnerability arises from improper validation of the HTTP Host header, allowing a remote attacker to redirect users to an arbitrary domain. This can enable phishing or defacement by making clients believe they are interacting with a trusted site, although the description does not confirm such misuse beyond the redirection capability.
Affected Systems
IBM Common Licensing Agent versions 9.0, 9.0.0.1, and 9.0.0.2, as well as the ART components 9.0, 9.0.0.1, and 9.0.0.2, are affected. These components are part of the IBM Common Licensing suite used for license management and reporting.
Risk and Exploitability
The CVSS base score of 9.1 indicates a high severity. The EPSS score is not available, so precise exploitation probability cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. The flaw can be exploited remotely over the network; an attacker only needs to send an HTTP request with a crafted Host header to the service. The ability to redirect users to arbitrary domains may facilitate phishing or defacement attacks.
OpenCVE Enrichment