These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
IBM Langflow OSS versions 1.0.0 through 1.9.0 contain a denial-of-service vulnerability stemming from uncontrolled resource consumption. The issue was published to the CVE Program on 2026-05-27 and carries a CVSS 3.1 score of 7.1 (HIGH). The attack vector is network-based with low attack complexity, requiring low privileges but no user interaction. The confidentiality impact is low, integrity impact is no [truncated]
A critical vulnerability in IBM Langflow OSS versions 1.0.0 through 1.9.1 allows remote code execution through improper validation of symbolic links during archive extraction. The vulnerability, published on 2026-05-27, stems from a path traversal weakness (CWE-22) where symbolic links in archives are not properly validated, potentially allowing attackers to write files to arbitrary locations on the files [truncated]
IBM Operations Analytics - Log Analysis and IBM SmartCloud Analytics - Log Analysis ship with default passwords from the manufacturing process intended for use during installation. These credentials are not changed post-installation, allowing an unauthenticated attacker with local access to bypass authentication and gain full control (confidentiality, integrity, and availability impact). The vulnerability [truncated]
IBM OpenBMC firmware versions FW1110.00 through FW1110.11 are vulnerable to denial of service attacks that can be launched by unauthenticated network users. The vulnerability has a CVSS 3.1 score of 5.3 (Medium severity) with a vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L, indicating network-based attack with low complexity, no privileges required, and low availability impact. The weakness is ca [truncated]
IBM Db2 12.1.0 through 12.1.4 contains an authorization bypass vulnerability affecting remote object storage uploads. An authenticated attacker with low privileges can exploit improper authorization checks (CWE-285) via a specially crafted query parameter to bypass intended access controls when uploading to remote object storage paths. The vulnerability has network attack vector, low attack complexity, an [truncated]
IBM i versions 7.3 through 7.6 contain a denial-of-service vulnerability in the Integrated Language Environment (ILE) compiler. The flaw stems from uncontrolled recursion (CWE-674) when processing specially crafted source code containing a specific combination of statements. An authenticated attacker with compilation privileges can trigger this condition, causing the compiler to exhaust system resources a [truncated]
IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4 contain a denial-of-service vulnerability triggered when a specially crafted query is executed against range-partitioned tables. The vulnerability, published 2026-05-27, carries a CVSS 3.1 score of 5.5 (MEDIUM) with an attack vector requiring local access and low privileges. The underlying weakness is categorized as CWE-770 (Allocation of Re [truncated]
IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4 are vulnerable to memory exhaustion when executing specific queries against Multi-Dimensional Clustering (MDC) tables. The vulnerability, classified as CWE-400 (Uncontrolled Resource Consumption), allows an authenticated attacker with low privileges to cause a denial of service condition by triggering memory depletion through network-accessi [truncated]
IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4 contain a denial-of-service vulnerability. An authenticated local attacker can trigger the condition by executing a specially crafted query when the database instance is configured with a small statement heap. The flaw stems from improper resource management (CWE-400), leading to uncontrolled resource consumption that crashes the database se [truncated]
IBM WebSphere Application Server Liberty 22.0.0.11 through 26.0.0.5 contains a medium-severity timing window vulnerability that could allow remote attackers to bypass security controls under limited conditions. The vulnerability requires high attack complexity and high privileges to exploit, with network access but no user interaction needed. Successful exploitation results in high confidentiality impact [truncated]
IBM App Connect Enterprise versions 13.0.1.0 through 13.0.7.0 stores potentially sensitive information in log files that could be read by a local user. This vulnerability represents an information disclosure risk where authenticated local users with appropriate file system permissions could access sensitive data written to application logs. The CVSS 3.1 vector (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N) indicat [truncated]
IBM Controller versions 11.0.1, 11.1.0, 11.1.1, and 11.1.2 contain hard-coded credentials used for inbound authentication, outbound communication, or internal data encryption. The vulnerability was published on 2026-05-27 and carries a CVSS 3.1 score of 8.8 (HIGH). The weakness is categorized as CWE-798 (Use of Hard-coded Credentials). IBM has published a security bulletin with remediation guidance.
IBM WebSphere Application Server Liberty versions 19.0.0.7 through 26.0.0.5, along with WebSphere Application Server 9.0 and 8.5, contain a denial-of-service vulnerability. A remote attacker can exploit this flaw by sending a specially crafted request, causing the server to consume excessive memory resources. The CVSS 3.1 vector (AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H) indicates this requires adjacent networ [truncated]
IBM Cloud APM 8.1.4 (Base Private and Advanced Private editions) contains a denial-of-service vulnerability in its Db2 Fenced environment query logic. An authenticated attacker can exploit improper neutralization of special elements (CWE-1284) to cause service disruption. The vulnerability is network-accessible with low attack complexity, requiring only low-privileged authentication. No confidentiality or [truncated]
IBM Netezza Performance Server Replication Services versions 3.0.2.0 through 3.0.5.0 contain a local privilege escalation vulnerability. An attacker with low-privileged access can escalate to root, enabling execution of root-level commands, acquisition of a root shell, and modification of the root password. Successful exploitation permits modification or removal of system-wide files and installation of pe [truncated]
IBM InfoSphere Optim Test Data Fabrication versions 1.0.0 through 1.0.2.7 contain a path traversal vulnerability (CWE-22) that could allow remote attackers to view arbitrary files on the system. The vulnerability stems from insufficient input validation on URL requests containing directory traversal sequences (/../). With a CVSS 3.1 score of 7.5 (HIGH severity), this vulnerability is network-exploitable w [truncated]
IBM MQ Operator and IBM-supplied MQ Advanced container images store potentially sensitive information in log files that could be read by a local user. The vulnerability affects multiple release streams: SC2 (v3.2.0 through 3.2.23, and container images 9.4.0.6 through 9.4.0.20-r1), CD (v3.3.0 through v3.9.1, and container images 9.4.1.0-r1 through 9.4.5.0-r2), and LTS (v2.0.0 through 2.0.29, and container [truncated]
IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4 contain a denial-of-service vulnerability triggered by specially crafted queries when autonomous transactions are enabled. The CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H) indicates network attack vector, low attack complexity, low privileges required, no user interaction, and high availability impact with limited confidentiality im [truncated]
IBM Cognos Analytics and IBM Cognos Transformer contain a stored cross-site scripting (XSS) vulnerability (CWE-79) affecting versions 11.2.0, 11.2.4, 12.0, and 12.1.0 (Analytics) and 11.2.4, 12.0, and 12.1.0 (Transformer). The vulnerability allows a remote attacker with low privileges to inject arbitrary JavaScript into the web UI, potentially altering functionality and disclosing credentials within a tru [truncated]
CVE-2024-56462 is a high-severity vulnerability affecting IBM QRadar versions 7.5.0 through 7.5.0 UP15 Interim Fix 002. The flaw allows a privileged user to upload a malicious backup archive that, when restored, can be leveraged to gain access to the underlying operating system. This represents a path traversal or arbitrary file write scenario within the backup restoration process, where insufficient vali [truncated]
IBM Operations Analytics - Log Analysis and IBM SmartCloud Analytics - Log Analysis do not enforce strong password requirements by default, allowing attackers to more easily compromise user accounts through weak or guessable credentials. The vulnerability affects versions 1.3.5.0 through 1.3.8.4. IBM has published a security bulletin with remediation guidance.
IBM Security Directory Integrator (SDI) versions 7.2.0.0 through 7.2.0.14 and 10.0.0.0 through 10.0.0.2 return overly verbose technical error messages to browser clients. These messages may expose internal system details—such as stack traces, file paths, or configuration parameters—that an unauthenticated remote attacker could harvest to refine subsequent targeting. The vulnerability is classified as CWE- [truncated]
IBM Engineering Lifecycle Management (ELM) versions 7.0.3, 7.1.0, and 7.2.0 contain an exposed method that is not properly restricted, allowing an attacker with administrative privileges to execute remote code. The vulnerability stems from improper access control (CWE-749) on an administrative interface method. The CVSS 3.1 vector indicates network attack vector, low attack complexity, high privileges req [truncated]
IBM Engineering Lifecycle Management (ELM) versions 7.0.3, 7.1.0, and 7.2.0 contain a critical authentication bypass vulnerability. An unauthenticated remote attacker can modify server property files to gain unauthorized administrative access to the application. The vulnerability is rated CVSS 3.1 9.8 (Critical) with network attack vector, low attack complexity, and no privileges or user interaction requi [truncated]
IBM Engineering Lifecycle Management versions 7.0.3, 7.1.0, and 7.2.0 contain an XML external entity injection (XXE) vulnerability. The flaw exists in XML data processing and can be exploited by an authenticated attacker to expose sensitive information or cause memory resource exhaustion. The vulnerability was published to the CVE Program on 26 May 2026 and carries a HIGH severity CVSS 3.1 score of 7.1. I [truncated]
IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty versions 8.5 and 9.0 contain an improper input validation vulnerability (CWE-444) that may allow denial of service and potential remote code execution. The vulnerability affects IBM WebSphere Application Server and WebSphere Application Server Liberty. IBM has published a security bulletin with remediation guidance. The NVD ent [truncated]
IBM HTTP Server versions 8.5 (prior to 8.5.5.30) and 9.0 (prior to 9.0.5.29) contain a denial-of-service vulnerability exploitable when an attacker has write access to portions of the server configuration. The CVSS 3.1 vector (AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H) indicates a local attack vector with low attack complexity, no privileges required, and no user interaction needed, resulting in high impact to [truncated]
IBM HTTP Server versions 8.5 (prior to 8.5.5.30) and 9.0 (prior to 9.0.5.29) contain a vulnerability in TLS mutual authentication (client authentication) configurations that enables remote code execution and denial of service. The vulnerability, published 2026-05-26, carries a CVSS 3.1 score of 8.1 (HIGH) with attack vector network, high attack complexity, and no required privileges or user interaction. T [truncated]
IBM HTTP Server versions 8.5 (prior to 8.5.5.30) and 9.0 (prior to 9.0.5.29) contain a denial-of-service vulnerability in the optional mod_mem_cache module. The flaw, classified as CWE-825 (Expired Pointer Dereference), allows network-based attackers to trigger high availability impact without authentication. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) indicates the vulnerability is exploita [truncated]
IBM HTTP Server versions 8.5 (prior to 8.5.5.30) and 9.0 (prior to 9.0.5.29) contain an invalid pointer dereference vulnerability in the Administration Server component. An authenticated privileged user can trigger this flaw to read sensitive information or cause denial of service. The vulnerability requires adjacent network access and low attack complexity, with confidentiality and availability impacts r [truncated]