IBM Common Licensing Agent 9.0、Agent 9.0.0.1、Agent 9.0.0.2、ART 9.0、ART 9.0.0.1 和 ART 9.0.0.2 仅在客户端执行输入验证,而未在服务器端强制执行相同的限制。攻击者可以修改请求以绕过验证控制,并提交未授权的值,从而导致非预期的应用程序行为。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| IBM | Common Licensing | Agent 9.0 |
affected |
Agent 9.0.0.1 |
affected | ||
Agent 9.0.0.2 |
affected | ||
ART 9.0 |
affected | ||
ART 9.0.0.1 |
affected | ||
ART 9.0.0.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| IBM | Common Licensing | Agent 9.0 |
cpe:2.3:a:ibm:common_licensing:agent:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-16338 | 9.9 CRITICAL | DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
| CVE-2026-16673 | 8.8 HIGH | DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
| CVE-2026-16466 | 8.8 HIGH | DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
| CVE-2026-16428 | 8.8 HIGH | DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
| CVE-2026-17467 | 8.2 HIGH | Vulnerabilities exists in IBM Cloud Pak for Data System |
| CVE-2026-16335 | 8.1 HIGH | DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
| CVE-2026-17416 | 7.8 HIGH | IBM App Connect Enterprise Toolkit is vulnerable to arbitrary code execution due to multip |
| CVE-2026-17156 | 7.8 HIGH | IBM App Connect Enterprise Toolkit is vulnerable to arbitrary code execution due to multip |
| CVE-2026-17133 | 7.8 HIGH | IBM App Connect Enterprise Toolkit is vulnerable to arbitrary code execution due to multip |
| CVE-2026-16432 | 7.7 HIGH | DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
| CVE-2026-15955 | 7.5 HIGH | IBM® Data Server driver for JDBC and SQLJ could allow a remote attacker to perform an arbi |
| CVE-2026-13107 | 7.1 HIGH | Multiple secuirty vulnerabilies addressed with IBM Business Automation Workflow August 202 |
| CVE-2026-53708 | 6.6 MEDIUM | ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/te |
| CVE-2026-16187 | 6.5 MEDIUM | IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple v |
| CVE-2026-12767 | 6.5 MEDIUM | Langflow is vulnerable to server-side request forgery due to missing egress validation on |
| CVE-2026-17463 | 6.5 MEDIUM | IBM® Db2® could allow a remote authenticated attacker to cause a denial of service due to |
| CVE-2026-16702 | 6.5 MEDIUM | IBM® Db2® federated server could allow a remote authenticated attacker to cause a denial o |
| CVE-2026-15396 | 6.5 MEDIUM | IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple v |
| CVE-2026-15412 | 6.5 MEDIUM | IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple v |
| CVE-2026-15634 | 6.5 MEDIUM | IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple v |
Showing top 20 of 39 CVEs. View all on vendor page → →
No comments yet