These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
IBM HTTP Server 8.5 and 9.0 contain a buffer overflow vulnerability in the Administration Server component. A privileged, authenticated attacker can exploit this flaw to achieve remote code execution or cause denial of service. The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow) and carries a CVSS 3.1 score of 8.0 (High severity). Affected versions include 8.5.0.0 through 8.5.5.29 and [truncated]
IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty versions 8.5 and 9.0 contain a critical remote code execution vulnerability. An unauthenticated attacker can exploit this flaw by sending a specially crafted request to achieve arbitrary code execution. The vulnerability resides in the Web Server Plug-ins component, which serves as the bridge between web servers and WebSphere a [truncated]
IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5 and 9.0 are vulnerable to HTTP request smuggling (CWE-444). The vulnerability allows attackers to manipulate HTTP request processing through specially crafted requests, potentially leading to security bypasses, cache poisoning, or unauthorized access to backend resources. The CVSS 3.1 vector (AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L [truncated]
IBM HTTP Server versions 8.5 (prior to 8.5.5.30) and 9.0 (prior to 9.0.5.29) contain a denial-of-service vulnerability in the optional mod_fastcgi module. The CVSS 3.1 vector (AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) indicates a local attack vector with low attack complexity, requiring no privileges or user interaction, resulting in high availability impact. The vulnerability is classified under CWE-617 (Reac [truncated]
IBM HTTP Server versions 8.5 (prior to 8.5.5.30) and 9.0 (prior to 9.0.5.29) contain a denial-of-service vulnerability in the optional mod_ibm_upload module. The vulnerability, classified as CWE-476 (NULL Pointer Dereference), allows unauthenticated remote attackers to cause availability impact with high severity (CVSS 3.1: 7.5). The affected module is not enabled by default, reducing exposure for standar [truncated]
IBM Cloud Pak for Data System - Cyclops versions 11.3.0.2 through Interim Fix 002 ship with default passwords from the manufacturing process that are used during installation. These credentials are not changed post-deployment, allowing network-based attackers to bypass authentication without prior access. The vulnerability is classified as CWE-1392 (Use of Default Credentials). IBM has published a securit [truncated]
A SQL injection vulnerability exists in IBM Cloud Pak for Data System - Cyclops versions 11.3.0.2 through Interim Fix 002. The vulnerability allows a remote, authenticated attacker to send specially crafted SQL statements that could enable viewing, adding, modifying, or deleting information in the back-end database. The CVSS 3.1 vector indicates network attack vector with low attack complexity, requiring [truncated]
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms versions 3.2.4.0 through 3.2.4.15 contains a cross-site scripting (XSS) vulnerability. An unauthenticated attacker can inject arbitrary JavaScript code into the Web UI, potentially leading to credential disclosure within a trusted session. The vulnerability was published to the NVD on 2026-05-26 and remains in 'Awaiting Analysis' stat [truncated]
IBM watsonx.data 2.2 through 2.3.1 contains a network access control weakness in its IBM Lakehouse component. The vulnerability stems from improper restriction of inbound and outbound connections, which could allow an authenticated attacker with low privileges to transfer or modify files without adequate restrictions. The CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N) indicates network attack vecto [truncated]
A stored cross-site scripting (XSS) vulnerability exists in IBM Cognos Analytics and IBM Cognos Transformer, affecting versions 11.2.0, 12.0, and 12.1.0 of Cognos Analytics and versions 11.2.4, 12.0, and 12.1.0 of Cognos Transformer. The vulnerability resides in the Cognos Administration Web UI component. A privileged attacker can embed arbitrary JavaScript code that executes within the context of a trust [truncated]
IBM webMethods Integration (on-premises) contains a server-side request forgery (SSRF) vulnerability affecting Integration Server versions 10.15 through IS_10.15_Core_Fix2611.1 and IS_11.1 through IS_11.1_Core_Fix10. An authenticated attacker can exploit this flaw to send unauthorized requests from the system, potentially enabling network enumeration or facilitating additional attacks. The vulnerability i [truncated]
IBM Db2 for Linux, UNIX, and Windows (versions 11.5.0–11.5.9 and 12.1.0–12.1.4, including DB2 Connect Server) stores potentially sensitive information in log files that could be read by a local user. The vulnerability is classified as CWE-532 (Insertion of Sensitive Information into Log File). With a CVSS 3.1 score of 5.5 (MEDIUM), the issue requires local access and low privileges, but results in high co [truncated]
CVE-2026-1577 is a medium-severity denial-of-service issue in IBM Db2 for Linux, UNIX, and Windows, including Db2 Connect Server. An authenticated user may be able to disrupt service by sending data that is not properly neutralized in query logic. The affected ranges called out in the CVE data are 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4. The issue was publicly disclosed on 2026-04-30 and the NVD r [truncated]
IBM Total Storage Service Console (TSSC) and TS4500 IMC versions 9.2 through 9.6 contain an unauthenticated command injection vulnerability (CWE-78) due to improper validation of user-supplied input. An attacker can execute arbitrary commands with normal user privileges without authentication. The vulnerability was published on April 23, 2026, and last modified on May 18, 2026. IBM has released a vendor a [truncated]
IBM Tivoli Netcool Impact versions 7.1.0.0 through 7.1.0.37 are affected by a vulnerability where sensitive information is stored in log files that could be accessed by a local user. This could potentially lead to information disclosure if an attacker gains local access to the system. The CVE was published on 2026-04-08T01:16:41.220Z and was last modified on 2026-07-24T20:10:00.147Z. The vulnerability has [truncated]
IBM Langflow Desktop 1.6.0 through 1.8.2 is vulnerable due to an insecure default setting that permits the deserialization of untrusted data in the FAISS component. This allows authenticated users to execute arbitrary code on the system. The vulnerability has a high CVSS score of 8.8, indicating high severity. Users should review system configurations and apply patches provided by IBM.
A locally authenticated user could execute malicious scripts from outside of its control sphere in IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1. This vulnerability allows a locally authenticated user to execute malicious scripts due to improper validation of user input. The affected products include IBM Verify Identity Access Conta [truncated]
IBM Maximo Application Suite 9.1, 9.0, 8.11, and 8.10 does not set the 'secure' attribute on authorization tokens or session cookies. An unauthenticated attacker can steal cookies by directing users to a malicious http:// link and snooping user traffic. This issue was fixed in versions 9.1.8, 9.0.19, 8.11.30, and 8.10.33. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 4.3, [truncated]
IBM Concert 1.0.0 through 2.2.0 creates temporary files with predictable names, allowing local users to overwrite arbitrary files via a symlink attack. This vulnerability has a CVSS score of 6.2 and is classified as MEDIUM severity. Users of affected versions should review and apply vendor guidance to mitigate potential impact. The vulnerability is a result of the application's insecure temporary file cre [truncated]
CVE-2025-13702 is a medium-severity cross-site scripting (XSS) issue in IBM Sterling Partner Engagement Manager. According to the CVE description, an authenticated user can embed arbitrary JavaScript in the Web UI, which can alter intended application behavior and may expose credentials within a trusted session. The CVE was published on 2026-03-13 and later modified on 2026-05-10.
IBM DevOps Plan 3.0.0 through 3.0.5 allows web page cache to be stored locally which can be read by another user on the system. This CVE was published on 2026-03-03T20:16:43.293Z and was last modified on 2026-07-27T18:14:38.763Z. The vulnerability class is related to local information disclosure. The CVSS score is 6.2 and the severity is MEDIUM. Affected users should review and update their systems to mit [truncated]
IBM DevOps Plan 3.0.0 through 3.0.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. The vulnerability affects IBM DevOps Plan versions 3.0.0 through 3.0.5, with a CVSS score of 5.9 and a severity of MEDIUM. Security teams should review and adjust account lockout settings, and consider upgrading to version 3.0.6 or later. Evidence is based o [truncated]
CVE-2022-47986 is a code execution vulnerability affecting IBM Aspera Faspex. CISA added it to the Known Exploited Vulnerabilities catalog on 2023-02-21 and marked it as associated with known ransomware campaign use. Based on the supplied sources, the safest response is to treat this as an urgent patching item and follow IBM’s update guidance as referenced by CISA.
CVE-2013-3993 is a CISA Known Exploited Vulnerability affecting IBM InfoSphere BigInsights. The supplied CISA KEV metadata identifies the issue as an invalid input vulnerability and states that the impacted product is end-of-life and should be disconnected if it is still in use. Because CISA has added it to the KEV catalog and marked known ransomware campaign use as known, this should be treated as a high [truncated]
CVE-2015-7450 is a code injection vulnerability affecting IBM WebSphere Application Server and Server Hypervisor Edition. CISA lists it in the Known Exploited Vulnerabilities catalog, which means defenders should treat it as an active exposure and prioritize vendor-directed remediation.
CVE-2020-4430 is a directory traversal vulnerability in IBM Data Risk Manager. CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03, which means defenders should treat it as a high-priority remediation item and follow IBM’s update guidance.
CVE-2020-4428 is an IBM Data Risk Manager remote code execution vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. Because it is marked as known exploited, it should be treated as a high-priority remediation item and addressed using IBM’s vendor instructions.
CVE-2020-4427 is a security bypass vulnerability affecting IBM Data Risk Manager. CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03, which means it should be treated as a high-priority remediation item. The supplied corpus does not include a CVSS score or deeper technical detail, so the safest defensive response is to follow IBM’s update guidance and verify exposure quickly.
CVE-2019-4716 is an IBM Planning Analytics remote code execution vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. That KEV listing means defenders should treat it as a priority remediation item and follow vendor guidance to update affected systems. The supplied source corpus does not provide additional technical detail, affected-version ranges, or exploitation conditions, so r [truncated]
CVE-2016-9994 is a SQL injection vulnerability in IBM Kenexa LCMS Premier on Cloud. The issue is documented with a CVSS 3.0 score of 7.1 (High) and can let an attacker interact with the back-end database to view, add, modify, or delete information. NVD lists vulnerable IBM Kenexa LCMS Premier versions including 9.0 through 9.5 and 10.0, and the IBM advisory referenced by NVD is the primary vendor remediation source.