CVE-2026-19646

Summary

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 could allow a remote attacker to redirect users to an arbitrary domain due to improper validation of the HTTP Host header.

Affected Software

VendorProductVersion RangeStatus
IBMCommon LicensingAgent 9.0affected
IBMCommon LicensingAgent 9.0.0.1affected
IBMCommon LicensingAgent 9.0.0.2affected
IBMCommon LicensingART 9.0affected
IBMCommon LicensingART 9.0.0.1affected
IBMCommon LicensingART 9.0.0.2affected

Weaknesses

  • CWE-1149: CWE-1149 SEI CERT Oracle Secure Coding Standard for Java - Guidelines 15. Platform Security (SEC)

References