These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
IBM watsonx.data intelligence versions 5.2.2, 5.3.0, 5.3.1, and 5.3.1 through Patch 1 are vulnerable to a clear text transmission issue. This vulnerability allows an attacker to obtain sensitive information using man-in-the-middle techniques. The affected product is used for data intelligence tasks. The vulnerability has a CVSS score of 5.9, classified as MEDIUM severity. IBM has provided patches and upda [truncated]
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.26 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 are vulnerable to SQL injection due to improper input validation. A remote attacker could socially engineer a user into accidentally creating files they may not be aware of. This vulnerability requires social engineering tactics to exploit and has a CVSS score of [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-06-30T20:17:28.033Z and has not been modified since then. IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled. This vulnerability has a CVSS score of 8.5 and is classified as HIGH severity. Organizations should re [truncated]
IBM Langflow OSS versions 1.0.0 through 1.10.0 contain improper shared-state handling, allowing reuse of API clients across tenant boundaries. An authenticated attacker can manipulate cache state to cause requests from other users to be processed using incorrect upstream API credentials. This results in cross-tenant billing and accountability misattribution. The vulnerability affects IBM Langflow OSS inst [truncated]
CVE-2026-9610 is a vulnerability in IBM Datacap and Datacap Navigator versions 9.1.7, 9.1.8, and 9.1.9. The vulnerability allows unauthorized access to resources or functionality that is not linked in the UI but can be accessed directly via URL requests, bypassing intended access controls. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 2.3, indicating a low severity. The CV [truncated]
CVE-2026-9320 is a denial of service vulnerability in IBM WebSphere Application Server. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. The vulnerability affects IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6. IBM has released a vendor advisory to address this issue. Users should rev [truncated]
CVE-2026-9072 is a high-severity vulnerability affecting IBM WebSphere Application Server and IBM WebSphere Application Server Liberty. The vulnerability occurs when using Intelligent Management with the WebSphere WebServer Plug-in component, allowing for remote code execution and denial of service attacks. An attacker can exploit this vulnerability by impersonating backend servers and sending crafted res [truncated]
CVE-2026-9071 is a denial of service vulnerability in IBM WebSphere Application Server 9.0, 8.5, and Liberty 17.0.0.3 through 26.0.0.6. A remote attacker could exploit this vulnerability by sending a specially-crafted request, causing the server to consume memory resources. This issue has a CVSS score of 7.5 and is considered HIGH severity. IBM has provided a vendor advisory for mitigation. The CVE was pu [truncated]
CVE-2026-9006 is a high-severity vulnerability in IBM WebSphere Application Server 9.0 and 8.5, allowing for server-side request forgery (SSRF) attacks when the Ajax Proxy is configured. This vulnerability may enable an attacker to send unauthorized requests from the system, potentially leading to security bypass or information disclosure. The CVSS score for this vulnerability is 7.4, indicating a high le [truncated]
CVE-2026-8646 is a high-severity vulnerability in IBM WebSphere Application Server. The vulnerability allows remote attackers to smuggle specially crafted requests, potentially bypassing security controls, spoofing identity, escalating privilege, and exposing sensitive information. This issue affects WebSphere Application Server 9.0, 8.5, and Liberty versions 17.0.0.3 through 26.0.0.6. IBM has provided a [truncated]
CVE-2026-7664 is a critical vulnerability in IBM Langflow OSS versions 1.0.0 through 1.8.4. The vulnerability allows unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint. The CVSS score for this vulnerability is 9.8, indicating a critical severity. IBM has provided a vendor advisory [truncated]
CVE-2026-12628 is a critical vulnerability in IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8.1.0.0 through 8.2.1.0. The vulnerability allows a remote attacker to bypass authentication due to the use of a hardcoded credential in the FlashCopy Manager (FCM) authentication mechanism. The application contains a static credential embedded in multiple authentic [truncated]
CVE-2026-10845 is a high-severity vulnerability in IBM WebSphere Application Server 8.5 and 9.0 that allows remote attackers to bypass authentication and gain unauthorized access to JAX-WS applications. The vulnerability has a CVSS score of 7.3 and is considered high severity. IBM has provided a vendor advisory for mitigation. Users should review their WebSphere Application Server versions 8.5.0.0 to 8.5. [truncated]
IBM Engineering Workflow Management is vulnerable to HTTP header injection due to improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning, or session hijacking. The vulnerability affects multiple versions of Engineering Workflow Management, including 7.0.2 through 7.0.2 Interim [truncated]
CVE-2023-33854 is a medium-severity vulnerability affecting IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data. An authenticated user could bypass client-side validation and manipulate input data using man-in-the-middle techniques. The vulnerability has a CVSS score of 5.3. IBM has provided a reference for this issue. Users should review their inventory and apply patches as available. A [truncated]
CVE-2025-2669 is a medium-severity vulnerability affecting IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, 5.3. A privileged user could exploit improper token validation to perform unauthorized operations and access sensitive information. Defenders should assess exposure and prioritize patching due to potential insider threats.
CVE-2024-54178 is a medium-severity vulnerability affecting IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, and 5.3. An authenticated user could exploit this vulnerability to cause a denial of service when creating new databases due to improper allocation of resources. Defenders should assess their exposure and prioritize patching, as the CVSS score is 6.5.
CVE-2026-4870 is a HIGH severity vulnerability in IBM Qiskit SDK versions 0.43.0 through 2.5.0. The vulnerability could allow an attacker to trigger a segmentation fault leading to a denial of service due to uncontrolled recursion in the parser. The CVSS score for this vulnerability is 7.5.
CVE-2026-7870 is a high-severity vulnerability in IBM i 7.6, 7.5, 7.4, and 7.3 that allows a user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privilege. The vulnerability has a CVSS score of 8.8 and is classified as HIGH.
CVE-2026-7787 is a HIGH-severity vulnerability in IBM Langflow OSS versions 1.0.0 through 1.9.1. An authenticated user could exploit this vulnerability to read or modify sensitive information by bypassing authentication using insecure direct object references. The vulnerability was published on [cve-org](https://www.cve.org/CVERecord?id=CVE-2026-7787) and has a CVSS score of 7.5.
CVE-2026-4096 is a medium-severity vulnerability affecting IBM DevOps Plan versions 3.0.0 through 3.0.6. The vulnerability is caused by improper validation of input by the HOST headers, leading to HTTP header injection. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning, or session hijacking.
CVE-2026-3341 is a server-side request forgery (SSRF) vulnerability in IBM Langflow Desktop 1.0.0 through 1.9.2. An authenticated attacker could send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. The vulnerability has a CVSS score of 5.4 and a severity of MEDIUM.
CVE-2024-45636 is a vulnerability in IBM Security QRadar EDR 3.12 through 3.12.24. The vulnerability allows a local privileged user to read user credentials stored in plain text.
IBM Business Automation Workflow containers and traditional deployments may leak database structure information through error messages. This information disclosure vulnerability (CWE-209) has a CVSS 3.1 score of 4.3 (MEDIUM severity). The issue was published to the NVD on 2026-05-27 and remains in 'Awaiting Analysis' status. The vulnerability requires network access and low privileges to exploit, with no [truncated]
IBM Aspera High-Speed Transfer Endpoint and Server versions 3.7.4 through 4.4.7 Fix Pack 1 contain an arbitrary file read vulnerability in the asperahttpd component. An authenticated attacker can exploit path traversal weaknesses (CWE-22) to access files outside intended directories on the server's local storage. The vulnerability requires network access and valid credentials, with no user interaction nee [truncated]
IBM Guardium Data Protection versions 12.2.1 and 12.2.2 contain an information disclosure vulnerability in the Long Term Retention (LTR) add-on feature. When debug mode is enabled, sensitive credentials may be exposed. The vulnerability is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) and carries a CVSS 3.1 score of 6.5 (MEDIUM severity). The attack vector is network-b [truncated]
IBM Aspera High-Speed Transfer Endpoint and Server versions 3.7.4 through 4.4.7 Fix Pack 1 contain a denial-of-service vulnerability in the asperahttpd component. An unauthenticated remote attacker can trigger a crash of the asperahttpd service. The vulnerability is classified as CWE-476 (NULL Pointer Dereference) and carries a CVSS 3.1 score of 7.5 (HIGH severity) with network attack vector, low attack c [truncated]
A buffer overflow vulnerability in IBM Aspera High-Speed Transfer Endpoint and Server versions 3.7.4 through 4.4.7 Fix Pack 1 allows authenticated remote attackers to execute arbitrary code on affected systems. The vulnerability resides in the asperahttpd component. The CVSS 3.1 score of 8.8 (High) reflects network attack vector, low attack complexity, low privileges required, and high impact to confident [truncated]
A critical buffer overflow vulnerability in IBM Aspera High-Speed Transfer Endpoint and Server versions 3.7.4 through 4.4.7 Fix Pack 1 affects the asperahttpd component. The vulnerability, classified as CWE-122 (Heap-based Buffer Overflow), carries a CVSS 3.1 score of 9.8 (Critical) due to network attack vector with low complexity, no privileges required, and no user interaction needed. Successful exploit [truncated]
IBM Aspera HSTS for Cloud Pak for Integration (CP4I) versions 1.5.1 through 1.5.19 contains an improper authentication vulnerability (CWE-287). The vulnerability was published by IBM PSIRT and indexed by NVD on 2026-05-27. No CVSS score or severity rating has been assigned as of the CVE modification time (2026-05-27T14:53:51.833Z); NVD status remains 'Awaiting Analysis'. The affected product is IBM Aspera [truncated]