CVE-2026-1025 PUBLISHED

Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent

Assigner: ibm
Reserved: 16.01.2026 Published: 18.09.2026 Updated: 18.09.2026

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS Score: 6.1

Product Status

Vendor IBM
Product Common Licensing
Versions
  • Version Agent 9.0 is affected
  • Version Agent 9.0.0.1 is affected
  • Version Agent 9.0.0.2 is affected
  • Version ART 9.0 is affected
  • Version ART 9.0.0.1 is affected
  • Version ART 9.0.0.2 is affected

Solutions

Download and install IBM Common Licensing 9.1 from Passport Advantage Users are strongly advised to update to the latest version (IBM Common Licensing 9.1) to mitigate any potential risks associated with these vulnerabilities.

References

Problem Types

  • CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE