CVE-2026-19543
6.2
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Summary
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 performs input validation exclusively on the client side and fails to enforce the same restrictions on the server side. An attacker can modify requests to bypass validation controls and submit unauthorized values, potentially resulting in unintended application behavior.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| IBM | Common Licensing | Agent 9.0 | affected |
| IBM | Common Licensing | Agent 9.0.0.1 | affected |
| IBM | Common Licensing | Agent 9.0.0.2 | affected |
| IBM | Common Licensing | ART 9.0 | affected |
| IBM | Common Licensing | ART 9.0.0.1 | affected |
| IBM | Common Licensing | ART 9.0.0.2 | affected |
Weaknesses
- CWE-20: CWE-20 Improper Input Validation
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.