Executive brief
IBM Common Licensing Agent and Administration and Reporting Tool (ART) are used to manage software licenses across enterprise systems. A flaw in these products allows remote attackers to redirect users to arbitrary websites through improper validation of the HTTP Host header, potentially capturing credentials or delivering malware without requiring authentication or user interaction.
Technical details
IBM Common Licensing Agent suffers from improper validation of the HTTP Host header, enabling an open redirect vulnerability. The vulnerable component fails to validate or sanitize the Host header before using it in redirect responses or generating URLs. An unauthenticated remote attacker can exploit this over the network by crafting a malicious request with a Host header pointing to an attacker-controlled domain, causing the application to redirect victims to arbitrary external sites. This can be leveraged for credential harvesting via phishing or malware distribution. Patches are available through IBM support.
Affected products
- IBM Common Licensing Agent 9.0, 9.0.0.1, 9.0.0.2
- IBM License Key Server Administration and Reporting Tool (ART) 9.0, 9.0.0.1, 9.0.0.2
Timeline
- 2026-09-10: disclosed