<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Common Licensing ART (9.0, 9.0.0.1, 9.0.0.2) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/common-licensing-art-9.0-9.0.0.1-9.0.0.2/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 10 Sep 2026 23:09:42 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/common-licensing-art-9.0-9.0.0.1-9.0.0.2/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Host Header Injection in IBM Common Licensing Agent and ART</title><link>https://feed.craftedsignal.io/briefs/2026-09-ibm-licensing-host-header/</link><pubDate>Thu, 10 Sep 2026 23:09:42 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-ibm-licensing-host-header/</guid><description>IBM Common Licensing Agent and ART versions 9.0 through 9.0.0.2 are vulnerable to an unauthenticated remote redirect attack via improper HTTP Host header validation.</description><content:encoded><![CDATA[<p>IBM Common Licensing Agent and IBM Common Licensing ART versions 9.0, 9.0.0.1, and 9.0.0.2 contain a critical vulnerability, tracked as CVE-2026-19646, resulting from the improper validation of the HTTP Host header. This flaw allows a remote, unauthenticated attacker to manipulate the Host header in incoming HTTP requests to force the application to redirect users to an arbitrary, attacker-controlled domain. This vulnerability facilitates phishing campaigns, credential harvesting, and the delivery of malicious content by abusing the trust associated with the targeted licensing infrastructure. With a CVSS base score of 9.1, this vulnerability poses a significant risk to organizations relying on these products for license management.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows attackers to perform open redirects through the licensing application. This can be weaponized to bypass security controls, trick users into visiting malicious websites, or conduct targeted social engineering attacks, potentially leading to widespread internal credential theft or compromise of administrative sessions within the corporate environment.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the remediation of all affected IBM Common Licensing Agent and ART instances. Monitor web server logs for suspicious requests containing modified Host headers that deviate from expected internal hostnames.</p>
<ul>
<li>Upgrade all instances of IBM Common Licensing Agent and ART to the latest patched version provided by IBM.</li>
<li>Implement strict HTTP Host header validation on load balancers or reverse proxies sitting in front of these services to reject requests with unexpected Host values.</li>
<li>Audit webserver access logs for anomalous redirects occurring from the licensing application paths to external domains.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category></item></channel></rss>