CVE-2026-19543

Summary

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 performs input validation exclusively on the client side and fails to enforce the same restrictions on the server side. An attacker can modify requests to bypass validation controls and submit unauthorized values, potentially resulting in unintended application behavior.

Affected Software

VendorProductVersion RangeStatus
IBMCommon LicensingAgent 9.0affected
IBMCommon LicensingAgent 9.0.0.1affected
IBMCommon LicensingAgent 9.0.0.2affected
IBMCommon LicensingART 9.0affected
IBMCommon LicensingART 9.0.0.1affected
IBMCommon LicensingART 9.0.0.2affected

Weaknesses

  • CWE-20: CWE-20 Improper Input Validation

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References