Executive brief
IBM's Common Licensing Agent is a web-based tool for managing software licenses. An attacker can inject malicious JavaScript code into the web interface without authentication, potentially stealing administrator credentials or modifying license data. This could allow an attacker to take control of licensing systems and gain unauthorized access to protected software.
Technical details
This is a reflected or stored cross-site scripting (CWE-79) vulnerability in the Web UI that requires user interaction (clicking a malicious link) but no authentication. An unauthenticated attacker can embed arbitrary JavaScript in the interface, allowing credential theft or session hijacking within a trusted user session. A fix is available from IBM.
Affected products
- IBM Common Licensing Agent 9.0, 9.0.0.1, 9.0.0.2
- IBM License Key Server Administration and Reporting Tool 9.0, 9.0.0.1, 9.0.0.2
Timeline
- 2026-09-18: disclosed