CVE-2026-19646
9.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Summary
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 could allow a remote attacker to redirect users to an arbitrary domain due to improper validation of the HTTP Host header.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| IBM | Common Licensing | Agent 9.0 | affected |
| IBM | Common Licensing | Agent 9.0.0.1 | affected |
| IBM | Common Licensing | Agent 9.0.0.2 | affected |
| IBM | Common Licensing | ART 9.0 | affected |
| IBM | Common Licensing | ART 9.0.0.1 | affected |
| IBM | Common Licensing | ART 9.0.0.2 | affected |
Weaknesses
- CWE-1149: CWE-1149 SEI CERT Oracle Secure Coding Standard for Java - Guidelines 15. Platform Security (SEC)
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.