Vulnerabilities > IBM > Common Licensing

DATE CVE VULNERABILITY TITLE RISK
2025-01-26 CVE-2023-50945 Unprotected Storage of Credentials vulnerability in IBM Common Licensing 9.0.0
IBM Common Licensing 9.0 stores user credentials in plain clear text which can be read by a local user.
local
low complexity
ibm CWE-256
5.5
2025-01-26 CVE-2023-50946 Incorrect Authorization vulnerability in IBM Common Licensing 9.0.0
IBM Common Licensing 9.0 could allow an authenticated user to modify a configuration file that they should not have access to due to a broken authorization mechanism.
network
low complexity
ibm CWE-863
6.5
2024-08-13 CVE-2024-40697 Weak Password Requirements vulnerability in IBM Common Licensing 9.0
IBM Common Licensing 9.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
network
low complexity
ibm CWE-521
7.5
2024-08-13 CVE-2024-41774 Cross-site Scripting vulnerability in IBM Common Licensing 9.0
IBM Common Licensing 9.0 is vulnerable to stored cross-site scripting.
network
low complexity
ibm CWE-79
4.8
2024-02-20 CVE-2023-50306 Information Exposure Through Discrepancy vulnerability in IBM Common Licensing 9.0
IBM Common Licensing 9.0 could allow a local user to enumerate usernames due to an observable response discrepancy.
local
low complexity
ibm CWE-203
3.3