PatchSiren

IBM CVE debriefs · Page 12

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH IBM CVE published 2026-05-27

CVE-2026-7528

IBM Langflow OSS versions 1.0.0 through 1.9.0 contain a denial-of-service vulnerability stemming from uncontrolled resource consumption. The issue was published to the CVE Program on 2026-05-27 and carries a CVSS 3.1 score of 7.1 (HIGH). The attack vector is network-based with low attack complexity, requiring low privileges but no user interaction. The confidentiality impact is low, integrity impact is no [truncated]

CRITICAL IBM CVE published 2026-05-27

CVE-2026-7524

A critical vulnerability in IBM Langflow OSS versions 1.0.0 through 1.9.1 allows remote code execution through improper validation of symbolic links during archive extraction. The vulnerability, published on 2026-05-27, stems from a path traversal weakness (CWE-22) where symbolic links in archives are not properly validated, potentially allowing attackers to write files to arbitrary locations on the files [truncated]

HIGH IBM CVE published 2026-05-27

CVE-2026-7365

IBM Operations Analytics - Log Analysis and IBM SmartCloud Analytics - Log Analysis ship with default passwords from the manufacturing process intended for use during installation. These credentials are not changed post-installation, allowing an unauthenticated attacker with local access to bypass authentication and gain full control (confidentiality, integrity, and availability impact). The vulnerability [truncated]

MEDIUM IBM CVE published 2026-05-27

CVE-2026-7254

IBM OpenBMC firmware versions FW1110.00 through FW1110.11 are vulnerable to denial of service attacks that can be launched by unauthenticated network users. The vulnerability has a CVSS 3.1 score of 5.3 (Medium severity) with a vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L, indicating network-based attack with low complexity, no privileges required, and low availability impact. The weakness is ca [truncated]

MEDIUM IBM CVE published 2026-05-27

CVE-2026-6938

IBM Db2 12.1.0 through 12.1.4 contains an authorization bypass vulnerability affecting remote object storage uploads. An authenticated attacker with low privileges can exploit improper authorization checks (CWE-285) via a specially crafted query parameter to bypass intended access controls when uploading to remote object storage paths. The vulnerability has network attack vector, low attack complexity, an [truncated]

MEDIUM IBM CVE published 2026-05-27

CVE-2026-6936

IBM i versions 7.3 through 7.6 contain a denial-of-service vulnerability in the Integrated Language Environment (ILE) compiler. The flaw stems from uncontrolled recursion (CWE-674) when processing specially crafted source code containing a specific combination of statements. An authenticated attacker with compilation privileges can trigger this condition, causing the compiler to exhaust system resources a [truncated]

MEDIUM IBM CVE published 2026-05-27

CVE-2026-6053

IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4 contain a denial-of-service vulnerability triggered when a specially crafted query is executed against range-partitioned tables. The vulnerability, published 2026-05-27, carries a CVSS 3.1 score of 5.5 (MEDIUM) with an attack vector requiring local access and low privileges. The underlying weakness is categorized as CWE-770 (Allocation of Re [truncated]

MEDIUM IBM CVE published 2026-05-27

CVE-2026-6052

IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4 are vulnerable to memory exhaustion when executing specific queries against Multi-Dimensional Clustering (MDC) tables. The vulnerability, classified as CWE-400 (Uncontrolled Resource Consumption), allows an authenticated attacker with low privileges to cause a denial of service condition by triggering memory depletion through network-accessi [truncated]

MEDIUM IBM CVE published 2026-05-27

CVE-2026-6051

IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4 contain a denial-of-service vulnerability. An authenticated local attacker can trigger the condition by executing a specially crafted query when the database instance is configured with a small statement heap. The flaw stems from improper resource management (CWE-400), leading to uncontrolled resource consumption that crashes the database se [truncated]

MEDIUM IBM CVE published 2026-05-27

CVE-2026-5516

IBM WebSphere Application Server Liberty 22.0.0.11 through 26.0.0.5 contains a medium-severity timing window vulnerability that could allow remote attackers to bypass security controls under limited conditions. The vulnerability requires high attack complexity and high privileges to exploit, with network access but no user interaction needed. Successful exploitation results in high confidentiality impact [truncated]

MEDIUM IBM CVE published 2026-05-27

CVE-2026-5515

IBM App Connect Enterprise versions 13.0.1.0 through 13.0.7.0 stores potentially sensitive information in log files that could be read by a local user. This vulnerability represents an information disclosure risk where authenticated local users with appropriate file system permissions could access sensitive data written to application logs. The CVSS 3.1 vector (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N) indicat [truncated]

HIGH IBM CVE published 2026-05-27

CVE-2026-5065

IBM Controller versions 11.0.1, 11.1.0, 11.1.1, and 11.1.2 contain hard-coded credentials used for inbound authentication, outbound communication, or internal data encryption. The vulnerability was published on 2026-05-27 and carries a CVSS 3.1 score of 8.8 (HIGH). The weakness is categorized as CWE-798 (Use of Hard-coded Credentials). IBM has published a security bulletin with remediation guidance.

MEDIUM IBM CVE published 2026-05-27

CVE-2026-4410

IBM WebSphere Application Server Liberty versions 19.0.0.7 through 26.0.0.5, along with WebSphere Application Server 9.0 and 8.5, contain a denial-of-service vulnerability. A remote attacker can exploit this flaw by sending a specially crafted request, causing the server to consume excessive memory resources. The CVSS 3.1 vector (AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H) indicates this requires adjacent networ [truncated]

MEDIUM IBM CVE published 2026-05-27

CVE-2026-3676

IBM Cloud APM 8.1.4 (Base Private and Advanced Private editions) contains a denial-of-service vulnerability in its Db2 Fenced environment query logic. An authenticated attacker can exploit improper neutralization of special elements (CWE-1284) to cause service disruption. The vulnerability is network-accessible with low attack complexity, requiring only low-privileged authentication. No confidentiality or [truncated]

HIGH IBM CVE published 2026-05-27

CVE-2026-3623

IBM Netezza Performance Server Replication Services versions 3.0.2.0 through 3.0.5.0 contain a local privilege escalation vulnerability. An attacker with low-privileged access can escalate to root, enabling execution of root-level commands, acquisition of a root shell, and modification of the root password. Successful exploitation permits modification or removal of system-wide files and installation of pe [truncated]

HIGH IBM CVE published 2026-05-27

CVE-2026-3366

IBM InfoSphere Optim Test Data Fabrication versions 1.0.0 through 1.0.2.7 contain a path traversal vulnerability (CWE-22) that could allow remote attackers to view arbitrary files on the system. The vulnerability stems from insufficient input validation on URL requests containing directory traversal sequences (/../). With a CVSS 3.1 score of 7.5 (HIGH severity), this vulnerability is network-exploitable w [truncated]

MEDIUM IBM CVE published 2026-05-27

CVE-2026-2607

IBM MQ Operator and IBM-supplied MQ Advanced container images store potentially sensitive information in log files that could be read by a local user. The vulnerability affects multiple release streams: SC2 (v3.2.0 through 3.2.23, and container images 9.4.0.6 through 9.4.0.20-r1), CD (v3.3.0 through v3.9.1, and container images 9.4.1.0-r1 through 9.4.5.0-r2), and LTS (v2.0.0 through 2.0.29, and container [truncated]

HIGH IBM CVE published 2026-05-27

CVE-2026-1718

IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4 contain a denial-of-service vulnerability triggered by specially crafted queries when autonomous transactions are enabled. The CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H) indicates network attack vector, low attack complexity, low privileges required, no user interaction, and high availability impact with limited confidentiality im [truncated]

MEDIUM IBM CVE published 2026-05-27

CVE-2025-3633

IBM Cognos Analytics and IBM Cognos Transformer contain a stored cross-site scripting (XSS) vulnerability (CWE-79) affecting versions 11.2.0, 11.2.4, 12.0, and 12.1.0 (Analytics) and 11.2.4, 12.0, and 12.1.0 (Transformer). The vulnerability allows a remote attacker with low privileges to inject arbitrary JavaScript into the web UI, potentially altering functionality and disclosing credentials within a tru [truncated]

HIGH IBM CVE published 2026-05-27

CVE-2024-56462

CVE-2024-56462 is a high-severity vulnerability affecting IBM QRadar versions 7.5.0 through 7.5.0 UP15 Interim Fix 002. The flaw allows a privileged user to upload a malicious backup archive that, when restored, can be leveraged to gain access to the underlying operating system. This represents a path traversal or arbitrary file write scenario within the backup restoration process, where insufficient vali [truncated]

MEDIUM IBM CVE published 2026-05-27

CVE-2024-40684

IBM Operations Analytics - Log Analysis and IBM SmartCloud Analytics - Log Analysis do not enforce strong password requirements by default, allowing attackers to more easily compromise user accounts through weak or guessable credentials. The vulnerability affects versions 1.3.5.0 through 1.3.8.4. IBM has published a security bulletin with remediation guidance.

MEDIUM IBM CVE published 2026-05-27

CVE-2024-28765

IBM Security Directory Integrator (SDI) versions 7.2.0.0 through 7.2.0.14 and 10.0.0.0 through 10.0.0.2 return overly verbose technical error messages to browser clients. These messages may expose internal system details—such as stack traces, file paths, or configuration parameters—that an unauthenticated remote attacker could harvest to refine subsequent targeting. The vulnerability is classified as CWE- [truncated]

HIGH IBM CVE published 2026-05-26

CVE-2026-4051

IBM Engineering Lifecycle Management (ELM) versions 7.0.3, 7.1.0, and 7.2.0 contain an exposed method that is not properly restricted, allowing an attacker with administrative privileges to execute remote code. The vulnerability stems from improper access control (CWE-749) on an administrative interface method. The CVSS 3.1 vector indicates network attack vector, low attack complexity, high privileges req [truncated]

CRITICAL IBM CVE published 2026-05-26

CVE-2026-3660

IBM Engineering Lifecycle Management (ELM) versions 7.0.3, 7.1.0, and 7.2.0 contain a critical authentication bypass vulnerability. An unauthenticated remote attacker can modify server property files to gain unauthorized administrative access to the application. The vulnerability is rated CVSS 3.1 9.8 (Critical) with network attack vector, low attack complexity, and no privileges or user interaction requi [truncated]

HIGH IBM CVE published 2026-05-26

CVE-2026-3603

IBM Engineering Lifecycle Management versions 7.0.3, 7.1.0, and 7.2.0 contain an XML external entity injection (XXE) vulnerability. The flaw exists in XML data processing and can be exploited by an authenticated attacker to expose sensitive information or cause memory resource exhaustion. The vulnerability was published to the CVE Program on 26 May 2026 and carries a HIGH severity CVSS 3.1 score of 7.1. I [truncated]

CRITICAL IBM CVE published 2026-05-26

CVE-2026-9170

IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty versions 8.5 and 9.0 contain an improper input validation vulnerability (CWE-444) that may allow denial of service and potential remote code execution. The vulnerability affects IBM WebSphere Application Server and WebSphere Application Server Liberty. IBM has published a security bulletin with remediation guidance. The NVD ent [truncated]

HIGH IBM CVE published 2026-05-26

CVE-2026-8856

IBM HTTP Server versions 8.5 (prior to 8.5.5.30) and 9.0 (prior to 9.0.5.29) contain a denial-of-service vulnerability exploitable when an attacker has write access to portions of the server configuration. The CVSS 3.1 vector (AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H) indicates a local attack vector with low attack complexity, no privileges required, and no user interaction needed, resulting in high impact to [truncated]

HIGH IBM CVE published 2026-05-26

CVE-2026-8855

IBM HTTP Server versions 8.5 (prior to 8.5.5.30) and 9.0 (prior to 9.0.5.29) contain a vulnerability in TLS mutual authentication (client authentication) configurations that enables remote code execution and denial of service. The vulnerability, published 2026-05-26, carries a CVSS 3.1 score of 8.1 (HIGH) with attack vector network, high attack complexity, and no required privileges or user interaction. T [truncated]

HIGH IBM CVE published 2026-05-26

CVE-2026-8854

IBM HTTP Server versions 8.5 (prior to 8.5.5.30) and 9.0 (prior to 9.0.5.29) contain a denial-of-service vulnerability in the optional mod_mem_cache module. The flaw, classified as CWE-825 (Expired Pointer Dereference), allows network-based attackers to trigger high availability impact without authentication. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) indicates the vulnerability is exploita [truncated]

HIGH IBM CVE published 2026-05-26

CVE-2026-8835

IBM HTTP Server versions 8.5 (prior to 8.5.5.30) and 9.0 (prior to 9.0.5.29) contain an invalid pointer dereference vulnerability in the Administration Server component. An authenticated privileged user can trigger this flaw to read sensitive information or cause denial of service. The vulnerability requires adjacent network access and low attack complexity, with confidentiality and availability impacts r [truncated]