Executive brief
IBM Common Licensing Agent generates error messages that leak sensitive information about the system environment, user accounts, and internal data. An attacker with valid credentials can trigger these error messages to gather reconnaissance information useful for further attacks on the licensing infrastructure.
Technical details
The vulnerability is an information disclosure flaw (CWE-209) where error handling in IBM Common Licensing Agent exposes sensitive environmental data. The attack requires authentication (PR:L) and network access (AV:N), allowing an authenticated attacker to extract confidential information about the system without modifying data or causing denial of service.
Affected products
- IBM Common Licensing Agent 9.0, 9.0.0.1, 9.0.0.2
- IBM License Key Server Administration and Reporting Tool 9.0, 9.0.0.1, 9.0.0.2
Timeline
- 2026-09-18: disclosed