Common Licensing IBM Common Licensing

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in IBM Common Licensing.

By the Year

In 2026 there have been 1 vulnerability in IBM Common Licensing with an average score of 9.1 out of ten. Last year, in 2025 Common Licensing had 2 security vulnerabilities published. Right now, Common Licensing is on track to have less security vulnerabilities in 2026 than it did last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 3.10.

Year Vulnerabilities Average Score
2026 1 9.10
2025 2 6.00
2024 3 5.20

It may take a day or so for new Common Licensing vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent IBM Common Licensing Security Vulnerabilities

IBM Common Licensing Agent 9.0 Host Header Validation Allows Remote Redirection
CVE-2026-19646 9.1 - Critical - September 10, 2026

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 could allow a remote attacker to redirect users to an arbitrary domain due to improper validation of the HTTP Host header.

SEC

IBM Common Licensing 9.0 Auth Bypass Allows Unauthorized Config File Modification
CVE-2023-50946 6.5 - Medium - January 26, 2025

IBM Common Licensing 9.0 could allow an authenticated user to modify a configuration file that they should not have access to due to a broken authorization mechanism.

AuthZ

IBM Common Licensing 9.0 stores credentials in clear text
CVE-2023-50945 5.5 - Medium - January 26, 2025

IBM Common Licensing 9.0 stores user credentials in plain clear text which can be read by a local user.

Insufficiently Protected Credentials

IBM Common Licensing 9.0 XSS (stored) via Web UI privileged user
CVE-2024-41774 4.8 - Medium - August 13, 2024

IBM Common Licensing 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 350348.

XSS

IBM Common Licensing 9.0 Weak Password Policy Exposes Accounts
CVE-2024-40697 7.5 - High - August 13, 2024

IBM Common Licensing 9.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 297895.

Weak Password Requirements

IBM Common Licensing 9.0: Username Enumeration via Response Discrepancy
CVE-2023-50306 3.3 - Low - February 20, 2024

IBM Common Licensing 9.0 could allow a local user to enumerate usernames due to an observable response discrepancy. IBM X-Force ID: 273337.

Side Channel Attack

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for IBM Common Licensing or by IBM? Click the Watch button to subscribe.

IBM
Vendor

subscribe