Description
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 could allow a remote attacker to redirect users to an arbitrary domain due to improper validation of the HTTP Host header.
Published: 2026-09-10
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: HTTP Host header manipulation leading to user redirection
Action: Patch
AI Analysis

Impact

The vulnerability arises from improper validation of the HTTP Host header, allowing a remote attacker to redirect users to an arbitrary domain. This can enable phishing or defacement by making clients believe they are interacting with a trusted site, although the description does not confirm such misuse beyond the redirection capability.

Affected Systems

IBM Common Licensing Agent versions 9.0, 9.0.0.1, and 9.0.0.2, as well as the ART components 9.0, 9.0.0.1, and 9.0.0.2, are affected. These components are part of the IBM Common Licensing suite used for license management and reporting.

Risk and Exploitability

The CVSS base score of 9.1 indicates a high severity. The EPSS score is not available, so precise exploitation probability cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. The flaw can be exploited remotely over the network; an attacker only needs to send an HTTP request with a crafted Host header to the service. The ability to redirect users to arbitrary domains may facilitate phishing or defacement attacks.

Generated by OpenCVE AI on September 11, 2026 at 03:55 UTC.

Remediation

Vendor Solution

Download and install IBM Common Licensing 9.1 from Passport Advantage https://www.ibm.com/software/passportadvantage/pao-customer Users are strongly advised to update to the latest version (IBM Common Licensing 9.1) to mitigate any potential risks associated with these vulnerabilities.


OpenCVE Recommended Actions

  • Download and install IBM Common Licensing 9.1 from Passport Advantage.
  • Apply the update to all affected Agent and ART installations.
  • If an immediate update is not feasible, restrict traffic to known legitimate host headers using network filtering or firewall rules to mitigate the redirection risk.

Generated by OpenCVE AI on September 11, 2026 at 03:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Description IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 could allow a remote attacker to redirect users to an arbitrary domain due to improper validation of the HTTP Host header.
Title Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent
First Time appeared Ibm
Ibm common Licensing
Weaknesses CWE-1149
CPEs cpe:2.3:a:ibm:common_licensing:agent:*:*:*:*:*:*:*
cpe:2.3:a:ibm:common_licensing:art:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm common Licensing
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Ibm Common Licensing
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-11T17:04:13.786Z

Reserved: 2026-08-12T17:15:54.329Z

Link: CVE-2026-19646

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-10T22:16:55.697

Modified: 2026-09-11T14:56:50.613

Link: CVE-2026-19646

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T06:45:06Z

Weaknesses