Refine your search

144 vulnerabilities found for Db2 by IBM

CERTFR-2026-AVI-1094
Vulnerability from certfr_avis

De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

Solutions

Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

Impacted products
Vendor Product Description
IBM WebSphere WebSphere Application Server Liberty versions 17.0.0.3 à 26.0.0.7 sans le correctif de sécurité PH71585
IBM QRadar QRadar SIEM versions 7.5.x antérieures à 7.5.0 UP15 IF06
IBM Tivoli Tivoli System Automation Application Manager version 4.1 avec WebSphere Application Server sans les derniers correctifs de sécurité
IBM Sterling Sterling Control Center version 6.3.1.0 antérieure à 6.3.1.0 iFix11
IBM Db2 Db2 versions 11.5.x antérieures à 11.5.9 sans le dernier correctif de sécurité
IBM Sterling Sterling Connect:Direct File Agent versions 1.4.0.3x à 1.4.0.5x antérieures à 1.4.0.5_iFix016
IBM Db2 Db2 versions 12.1.x antérieures à 12.1.4 sans le dernier correctif de sécurité
IBM Spectrum Spectrum Control versions antérieures à 5.5
IBM Sterling Sterling Control Center version 6.4.2.0 antérieure à 6.4.2.0 iFix06
IBM QRadar QRadar SIEM versions 7.6.x antérieures à 7.6.0.3
IBM QRadar Security QRadar EDR versions 3.12.x antérieures à 3.12.26
IBM WebSphere WebSphere Hybrid Edition version 5.1 sans les correctifs de sécurité APAR DT496328, DT496327 et DT497580
IBM Db2 Db2 Genius Hub & Agentics versions 1.1.x antérieures à 1.1.4
IBM Tivoli Tivoli Application Dependency Discovery Manager versions 7.3.0.0 à 7.3.0.12 avec WebSphere Application Server Liberty versions antérieures à 26.0.0.8
IBM WebSphere WebSphere Extreme Scale versions 8.6.1.x antérieures à 8.6.1.6 avec le correctif de sécurité PH72588
IBM Sterling Sterling Connect:Direct for Unix versions 6.3.0.x antérieures à 6.3.0.7.iFix026
IBM Sterling Sterling Connect:Direct for Unix versions 6.4.0.x antérieures à 6.4.0.6.iFix014
IBM QRadar QRadar Suite Software versions 1.10.12.0 à 1.11.10.0 antérieures à 1.11.12.0
IBM QRadar QRadar AI Assistant versions antérieures à 2.2.0
References
Bulletin de sécurité IBM 7285382 2026-08-27 vendor-advisory
Bulletin de sécurité IBM 7284666 2026-08-24 vendor-advisory
Bulletin de sécurité IBM 7285542 2026-08-28 vendor-advisory
Bulletin de sécurité IBM 7285272 2026-08-26 vendor-advisory
Bulletin de sécurité IBM 7285232 2026-08-26 vendor-advisory
Bulletin de sécurité IBM 7285472 2026-08-27 vendor-advisory
Bulletin de sécurité IBM 7285291 2026-08-26 vendor-advisory
Bulletin de sécurité IBM 7285470 2026-08-27 vendor-advisory
Bulletin de sécurité IBM 7285469 2026-08-27 vendor-advisory
Bulletin de sécurité IBM 7284528 2026-08-21 vendor-advisory
Bulletin de sécurité IBM 7285416 2026-08-27 vendor-advisory
Bulletin de sécurité IBM 7285376 2026-08-27 vendor-advisory
Bulletin de sécurité IBM 7285380 2026-08-27 vendor-advisory
Bulletin de sécurité IBM 7285275 2026-08-26 vendor-advisory
Bulletin de sécurité IBM 7285292 2026-08-26 vendor-advisory
Bulletin de sécurité IBM 7285234 2026-08-26 vendor-advisory
Bulletin de sécurité IBM 7285141 2026-08-26 vendor-advisory
Bulletin de sécurité IBM 7279466 2026-08-27 vendor-advisory
Bulletin de sécurité IBM 7284718 2026-08-24 vendor-advisory
Bulletin de sécurité IBM 7285509 2026-08-28 vendor-advisory
Bulletin de sécurité IBM 7285340 2026-08-27 vendor-advisory
Bulletin de sécurité IBM 7285513 2026-08-28 vendor-advisory
Bulletin de sécurité IBM 7285420 2026-08-27 vendor-advisory
Bulletin de sécurité IBM 7284710 2026-08-24 vendor-advisory
Bulletin de sécurité IBM 7285274 2026-08-26 vendor-advisory
Bulletin de sécurité IBM 7284653 2026-08-24 vendor-advisory
Bulletin de sécurité IBM 7285342 2026-08-27 vendor-advisory
Bulletin de sécurité IBM 7285539 2026-08-28 vendor-advisory
Bulletin de sécurité IBM 7284670 2026-08-24 vendor-advisory
Bulletin de sécurité IBM 7284806 2026-08-24 vendor-advisory

Show details on source website


{
  "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
  "affected_systems": [
    {
      "description": "WebSphere Application Server Liberty versions 17.0.0.3 \u00e0 26.0.0.7 sans le correctif de s\u00e9curit\u00e9 PH71585",
      "product": {
        "name": "WebSphere",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "QRadar SIEM versions 7.5.x ant\u00e9rieures \u00e0 7.5.0 UP15 IF06",
      "product": {
        "name": "QRadar",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Tivoli System Automation Application Manager version 4.1 avec WebSphere Application Server sans les derniers correctifs de s\u00e9curit\u00e9",
      "product": {
        "name": "Tivoli",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Sterling Control Center version 6.3.1.0 ant\u00e9rieure \u00e0 6.3.1.0 iFix11",
      "product": {
        "name": "Sterling",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Db2 versions 11.5.x ant\u00e9rieures \u00e0 11.5.9 sans le dernier correctif de s\u00e9curit\u00e9",
      "product": {
        "name": "Db2",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Sterling Connect:Direct File Agent versions 1.4.0.3x \u00e0 1.4.0.5x ant\u00e9rieures \u00e0 1.4.0.5_iFix016",
      "product": {
        "name": "Sterling",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Db2 versions 12.1.x ant\u00e9rieures \u00e0 12.1.4 sans le dernier correctif de s\u00e9curit\u00e9",
      "product": {
        "name": "Db2",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Spectrum Control versions ant\u00e9rieures \u00e0 5.5",
      "product": {
        "name": "Spectrum",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Sterling Control Center version 6.4.2.0 ant\u00e9rieure \u00e0 6.4.2.0 iFix06",
      "product": {
        "name": "Sterling",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "QRadar SIEM versions 7.6.x ant\u00e9rieures \u00e0 7.6.0.3",
      "product": {
        "name": "QRadar",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Security QRadar EDR versions 3.12.x ant\u00e9rieures \u00e0 3.12.26",
      "product": {
        "name": "QRadar",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "WebSphere Hybrid Edition version 5.1 sans les correctifs de s\u00e9curit\u00e9 APAR DT496328, DT496327 et DT497580",
      "product": {
        "name": "WebSphere",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Db2 Genius Hub \u0026 Agentics versions 1.1.x ant\u00e9rieures \u00e0 1.1.4",
      "product": {
        "name": "Db2",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Tivoli Application Dependency Discovery Manager versions 7.3.0.0 \u00e0 7.3.0.12 avec WebSphere Application Server Liberty versions ant\u00e9rieures \u00e0 26.0.0.8",
      "product": {
        "name": "Tivoli",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "WebSphere Extreme Scale versions 8.6.1.x ant\u00e9rieures \u00e0 8.6.1.6 avec le correctif de s\u00e9curit\u00e9 PH72588",
      "product": {
        "name": "WebSphere",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Sterling Connect:Direct for Unix versions 6.3.0.x ant\u00e9rieures \u00e0 6.3.0.7.iFix026",
      "product": {
        "name": "Sterling",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Sterling Connect:Direct for Unix versions 6.4.0.x ant\u00e9rieures \u00e0 6.4.0.6.iFix014",
      "product": {
        "name": "Sterling",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "QRadar Suite Software versions 1.10.12.0 \u00e0 1.11.10.0 ant\u00e9rieures \u00e0 1.11.12.0",
      "product": {
        "name": "QRadar",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "QRadar AI Assistant versions ant\u00e9rieures \u00e0 2.2.0",
      "product": {
        "name": "QRadar",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    }
  ],
  "affected_systems_content": "",
  "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
  "cves": [
    {
      "name": "CVE-2026-41411",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41411"
    },
    {
      "name": "CVE-2026-14380",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14380"
    },
    {
      "name": "CVE-2026-26007",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26007"
    },
    {
      "name": "CVE-2026-43198",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43198"
    },
    {
      "name": "CVE-2026-54293",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54293"
    },
    {
      "name": "CVE-2026-49978",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49978"
    },
    {
      "name": "CVE-2026-9697",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9697"
    },
    {
      "name": "CVE-2026-53540",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53540"
    },
    {
      "name": "CVE-2026-54283",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54283"
    },
    {
      "name": "CVE-2026-54369",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54369"
    },
    {
      "name": "CVE-2026-40466",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40466"
    },
    {
      "name": "CVE-2026-59724",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59724"
    },
    {
      "name": "CVE-2026-45505",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45505"
    },
    {
      "name": "CVE-2026-4878",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4878"
    },
    {
      "name": "CVE-2026-49476",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49476"
    },
    {
      "name": "CVE-2026-42588",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42588"
    },
    {
      "name": "CVE-2026-27205",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27205"
    },
    {
      "name": "CVE-2026-59205",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59205"
    },
    {
      "name": "CVE-2026-33845",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33845"
    },
    {
      "name": "CVE-2026-41254",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41254"
    },
    {
      "name": "CVE-2026-42253",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42253"
    },
    {
      "name": "CVE-2026-44405",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44405"
    },
    {
      "name": "CVE-2026-50645",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50645"
    },
    {
      "name": "CVE-2026-44289",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44289"
    },
    {
      "name": "CVE-2026-42041",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42041"
    },
    {
      "name": "CVE-2026-9679",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9679"
    },
    {
      "name": "CVE-2026-39892",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39892"
    },
    {
      "name": "CVE-2026-10050",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10050"
    },
    {
      "name": "CVE-2024-24762",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-24762"
    },
    {
      "name": "CVE-2026-42402",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42402"
    },
    {
      "name": "CVE-2026-42561",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42561"
    },
    {
      "name": "CVE-2025-14505",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-14505"
    },
    {
      "name": "CVE-2026-16184",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16184"
    },
    {
      "name": "CVE-2026-15328",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15328"
    },
    {
      "name": "CVE-2026-32286",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32286"
    },
    {
      "name": "CVE-2026-46227",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46227"
    },
    {
      "name": "CVE-2026-57455",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57455"
    },
    {
      "name": "CVE-2026-54514",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54514"
    },
    {
      "name": "CVE-2026-44293",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44293"
    },
    {
      "name": "CVE-2026-44290",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44290"
    },
    {
      "name": "CVE-2021-23336",
      "url": "https://www.cve.org/CVERecord?id=CVE-2021-23336"
    },
    {
      "name": "CVE-2026-55276",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55276"
    },
    {
      "name": "CVE-2026-48710",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48710"
    },
    {
      "name": "CVE-2026-16243",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16243"
    },
    {
      "name": "CVE-2026-9171",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9171"
    },
    {
      "name": "CVE-2025-47279",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-47279"
    },
    {
      "name": "CVE-2025-40026",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-40026"
    },
    {
      "name": "CVE-2026-47010",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47010"
    },
    {
      "name": "CVE-2026-69249",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69249"
    },
    {
      "name": "CVE-2026-54058",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54058"
    },
    {
      "name": "CVE-2026-55653",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55653"
    },
    {
      "name": "CVE-2026-41239",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41239"
    },
    {
      "name": "CVE-2026-46117",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46117"
    },
    {
      "name": "CVE-2026-59084",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59084"
    },
    {
      "name": "CVE-2026-45740",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45740"
    },
    {
      "name": "CVE-2025-14920",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-14920"
    },
    {
      "name": "CVE-2026-52993",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52993"
    },
    {
      "name": "CVE-2026-59725",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59725"
    },
    {
      "name": "CVE-2026-14739",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14739"
    },
    {
      "name": "CVE-2026-39824",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39824"
    },
    {
      "name": "CVE-2026-46605",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46605"
    },
    {
      "name": "CVE-2026-54275",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54275"
    },
    {
      "name": "CVE-2026-22013",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22013"
    },
    {
      "name": "CVE-2026-47057",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47057"
    },
    {
      "name": "CVE-2026-10846",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10846"
    },
    {
      "name": "CVE-2026-22018",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22018"
    },
    {
      "name": "CVE-2026-12505",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12505"
    },
    {
      "name": "CVE-2026-35469",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35469"
    },
    {
      "name": "CVE-2026-9698",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9698"
    },
    {
      "name": "CVE-2026-42015",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42015"
    },
    {
      "name": "CVE-2026-14528",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14528"
    },
    {
      "name": "CVE-2026-54278",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54278"
    },
    {
      "name": "CVE-2026-53538",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53538"
    },
    {
      "name": "CVE-2026-18499",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18499"
    },
    {
      "name": "CVE-2026-46113",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46113"
    },
    {
      "name": "CVE-2026-54515",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54515"
    },
    {
      "name": "CVE-2026-53550",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53550"
    },
    {
      "name": "CVE-2026-43279",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43279"
    },
    {
      "name": "CVE-2026-53071",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53071"
    },
    {
      "name": "CVE-2026-49157",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49157"
    },
    {
      "name": "CVE-2026-16221",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16221"
    },
    {
      "name": "CVE-2026-55798",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55798"
    },
    {
      "name": "CVE-2026-6790",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6790"
    },
    {
      "name": "CVE-2026-7246",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7246"
    },
    {
      "name": "CVE-2026-15308",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15308"
    },
    {
      "name": "CVE-2026-66143",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66143"
    },
    {
      "name": "CVE-2026-46331",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46331"
    },
    {
      "name": "CVE-2026-66144",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66144"
    },
    {
      "name": "CVE-2026-44494",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44494"
    },
    {
      "name": "CVE-2026-55153",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55153"
    },
    {
      "name": "CVE-2026-46209",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46209"
    },
    {
      "name": "CVE-2026-11541",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11541"
    },
    {
      "name": "CVE-2026-34282",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34282"
    },
    {
      "name": "CVE-2026-44618",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44618"
    },
    {
      "name": "CVE-2026-42036",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42036"
    },
    {
      "name": "CVE-2026-33236",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33236"
    },
    {
      "name": "CVE-2026-54475",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54475"
    },
    {
      "name": "CVE-2026-31692",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-31692"
    },
    {
      "name": "CVE-2026-44240",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44240"
    },
    {
      "name": "CVE-2026-55443",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55443"
    },
    {
      "name": "CVE-2026-65900",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65900"
    },
    {
      "name": "CVE-2026-33558",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33558"
    },
    {
      "name": "CVE-2026-53916",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53916"
    },
    {
      "name": "CVE-2026-53006",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53006"
    },
    {
      "name": "CVE-2026-43450",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43450"
    },
    {
      "name": "CVE-2026-33846",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33846"
    },
    {
      "name": "CVE-2026-42403",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42403"
    },
    {
      "name": "CVE-2026-34043",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34043"
    },
    {
      "name": "CVE-2026-59880",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59880"
    },
    {
      "name": "CVE-2026-15057",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15057"
    },
    {
      "name": "CVE-2026-59890",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59890"
    },
    {
      "name": "CVE-2026-53266",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53266"
    },
    {
      "name": "CVE-2025-64718",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-64718"
    },
    {
      "name": "CVE-2026-46116",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46116"
    },
    {
      "name": "CVE-2026-14742",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14742"
    },
    {
      "name": "CVE-2025-62718",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-62718"
    },
    {
      "name": "CVE-2026-44990",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44990"
    },
    {
      "name": "CVE-2026-47265",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47265"
    },
    {
      "name": "CVE-2026-49458",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49458"
    },
    {
      "name": "CVE-2026-54282",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54282"
    },
    {
      "name": "CVE-2026-46259",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46259"
    },
    {
      "name": "CVE-2026-0540",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0540"
    },
    {
      "name": "CVE-2026-45149",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45149"
    },
    {
      "name": "CVE-2026-45249",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45249"
    },
    {
      "name": "CVE-2026-23865",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23865"
    },
    {
      "name": "CVE-2026-48988",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48988"
    },
    {
      "name": "CVE-2026-43499",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43499"
    },
    {
      "name": "CVE-2026-11525",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11525"
    },
    {
      "name": "CVE-2026-15325",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15325"
    },
    {
      "name": "CVE-2026-59199",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59199"
    },
    {
      "name": "CVE-2026-69247",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69247"
    },
    {
      "name": "CVE-2026-33671",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33671"
    },
    {
      "name": "CVE-2026-34515",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34515"
    },
    {
      "name": "CVE-2026-14976",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14976"
    },
    {
      "name": "CVE-2026-48864",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48864"
    },
    {
      "name": "CVE-2026-34519",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34519"
    },
    {
      "name": "CVE-2026-42033",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42033"
    },
    {
      "name": "CVE-2026-42035",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42035"
    },
    {
      "name": "CVE-2026-54277",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54277"
    },
    {
      "name": "CVE-2026-69248",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69248"
    },
    {
      "name": "CVE-2026-18446",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18446"
    },
    {
      "name": "CVE-2026-5450",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5450"
    },
    {
      "name": "CVE-2026-14512",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14512"
    },
    {
      "name": "CVE-2026-5260",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5260"
    },
    {
      "name": "CVE-2026-42009",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42009"
    },
    {
      "name": "CVE-2026-54059",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54059"
    },
    {
      "name": "CVE-2026-10842",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10842"
    },
    {
      "name": "CVE-2026-46189",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46189"
    },
    {
      "name": "CVE-2026-33750",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33750"
    },
    {
      "name": "CVE-2026-5038",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5038"
    },
    {
      "name": "CVE-2026-40186",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40186"
    },
    {
      "name": "CVE-2026-2359",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2359"
    },
    {
      "name": "CVE-2026-42043",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42043"
    },
    {
      "name": "CVE-2026-44288",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44288"
    },
    {
      "name": "CVE-2026-41603",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41603"
    },
    {
      "name": "CVE-2026-8646",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8646"
    },
    {
      "name": "CVE-2026-45822",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45822"
    },
    {
      "name": "CVE-2026-6918",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6918"
    },
    {
      "name": "CVE-2026-55380",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55380"
    },
    {
      "name": "CVE-2026-54280",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54280"
    },
    {
      "name": "CVE-2026-46625",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46625"
    },
    {
      "name": "CVE-2026-25749",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25749"
    },
    {
      "name": "CVE-2026-44489",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44489"
    },
    {
      "name": "CVE-2026-12413",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12413"
    },
    {
      "name": "CVE-2026-59869",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59869"
    },
    {
      "name": "CVE-2026-3833",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3833"
    },
    {
      "name": "CVE-2025-13151",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-13151"
    },
    {
      "name": "CVE-2026-9320",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9320"
    },
    {
      "name": "CVE-2026-49459",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49459"
    },
    {
      "name": "CVE-2026-66053",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66053"
    },
    {
      "name": "CVE-2026-41044",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41044"
    },
    {
      "name": "CVE-2026-41043",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41043"
    },
    {
      "name": "CVE-2026-5079",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5079"
    },
    {
      "name": "CVE-2026-34518",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34518"
    },
    {
      "name": "CVE-2026-50734",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50734"
    },
    {
      "name": "CVE-2026-44930",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44930"
    },
    {
      "name": "CVE-2026-14974",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14974"
    },
    {
      "name": "CVE-2026-41240",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41240"
    },
    {
      "name": "CVE-2026-42010",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42010"
    },
    {
      "name": "CVE-2026-5435",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5435"
    },
    {
      "name": "CVE-2026-4427",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4427"
    },
    {
      "name": "CVE-2026-59887",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59887"
    },
    {
      "name": "CVE-2026-59203",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59203"
    },
    {
      "name": "CVE-2025-10263",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-10263"
    },
    {
      "name": "CVE-2026-42040",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42040"
    },
    {
      "name": "CVE-2026-47027",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47027"
    },
    {
      "name": "CVE-2026-23216",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23216"
    },
    {
      "name": "CVE-2026-47058",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47058"
    },
    {
      "name": "CVE-2026-42013",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42013"
    },
    {
      "name": "CVE-2026-62389",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62389"
    },
    {
      "name": "CVE-2026-12151",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12151"
    },
    {
      "name": "CVE-2026-5928",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5928"
    },
    {
      "name": "CVE-2026-16441",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16441"
    },
    {
      "name": "CVE-2026-27903",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27903"
    },
    {
      "name": "CVE-2026-14981",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14981"
    },
    {
      "name": "CVE-2026-6734",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6734"
    },
    {
      "name": "CVE-2026-12243",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12243"
    },
    {
      "name": "CVE-2025-6170",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-6170"
    },
    {
      "name": "CVE-2026-46150",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46150"
    },
    {
      "name": "CVE-2026-46090",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46090"
    },
    {
      "name": "CVE-2026-14529",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14529"
    },
    {
      "name": "CVE-2026-34525",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34525"
    },
    {
      "name": "CVE-2025-71089",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71089"
    },
    {
      "name": "CVE-2026-54274",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54274"
    },
    {
      "name": "CVE-2026-54512",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54512"
    },
    {
      "name": "CVE-2026-59197",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59197"
    },
    {
      "name": "CVE-2026-57819",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57819"
    },
    {
      "name": "CVE-2026-53059",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53059"
    },
    {
      "name": "CVE-2026-65899",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65899"
    },
    {
      "name": "CVE-2026-4539",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4539"
    },
    {
      "name": "CVE-2026-34197",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34197"
    },
    {
      "name": "CVE-2026-55956",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55956"
    },
    {
      "name": "CVE-2026-54060",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54060"
    },
    {
      "name": "CVE-2026-41140",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41140"
    },
    {
      "name": "CVE-2025-48913",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-48913"
    },
    {
      "name": "CVE-2026-59858",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59858"
    },
    {
      "name": "CVE-2026-42404",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42404"
    },
    {
      "name": "CVE-2026-45984",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45984"
    },
    {
      "name": "CVE-2026-53537",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53537"
    },
    {
      "name": "CVE-2026-40046",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40046"
    },
    {
      "name": "CVE-2026-16192",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16192"
    },
    {
      "name": "CVE-2026-50722",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50722"
    },
    {
      "name": "CVE-2026-3304",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3304"
    },
    {
      "name": "CVE-2026-46145",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46145"
    },
    {
      "name": "CVE-2026-54273",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54273"
    },
    {
      "name": "CVE-2026-40895",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40895"
    },
    {
      "name": "CVE-2026-42198",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42198"
    },
    {
      "name": "CVE-2026-47063",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47063"
    },
    {
      "name": "CVE-2026-14515",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14515"
    },
    {
      "name": "CVE-2026-22016",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22016"
    },
    {
      "name": "CVE-2026-22021",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22021"
    },
    {
      "name": "CVE-2026-59083",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59083"
    },
    {
      "name": "CVE-2026-25243",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25243"
    },
    {
      "name": "CVE-2026-46135",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46135"
    },
    {
      "name": "CVE-2026-22007",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22007"
    },
    {
      "name": "CVE-2026-58016",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58016"
    },
    {
      "name": "CVE-2026-43056",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43056"
    },
    {
      "name": "CVE-2026-59888",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59888"
    },
    {
      "name": "CVE-2026-13149",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13149"
    },
    {
      "name": "CVE-2026-47021",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47021"
    },
    {
      "name": "CVE-2025-54410",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-54410"
    },
    {
      "name": "CVE-2026-46054",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46054"
    },
    {
      "name": "CVE-2025-69873",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69873"
    },
    {
      "name": "CVE-2026-49434",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49434"
    },
    {
      "name": "CVE-2026-42011",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42011"
    },
    {
      "name": "CVE-2026-34268",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34268"
    },
    {
      "name": "CVE-2026-16440",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16440"
    },
    {
      "name": "CVE-2026-64958",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64958"
    },
    {
      "name": "CVE-2026-50721",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50721"
    },
    {
      "name": "CVE-2025-71066",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71066"
    },
    {
      "name": "CVE-2026-44291",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44291"
    },
    {
      "name": "CVE-2026-15043",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15043"
    },
    {
      "name": "CVE-2026-66373",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66373"
    },
    {
      "name": "CVE-2026-3520",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3520"
    },
    {
      "name": "CVE-2026-55693",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55693"
    },
    {
      "name": "CVE-2026-57456",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57456"
    },
    {
      "name": "CVE-2026-29786",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-29786"
    },
    {
      "name": "CVE-2026-44487",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44487"
    },
    {
      "name": "CVE-2026-2482",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2482"
    },
    {
      "name": "CVE-2026-11897",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11897"
    },
    {
      "name": "CVE-2026-42038",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42038"
    },
    {
      "name": "CVE-2026-49844",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49844"
    },
    {
      "name": "CVE-2026-31419",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-31419"
    },
    {
      "name": "CVE-2026-41680",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41680"
    },
    {
      "name": "CVE-2026-44292",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44292"
    },
    {
      "name": "CVE-2026-54370",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54370"
    },
    {
      "name": "CVE-2026-42039",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42039"
    },
    {
      "name": "CVE-2026-49432",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49432"
    },
    {
      "name": "CVE-2026-59879",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59879"
    },
    {
      "name": "CVE-2026-46968",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46968"
    },
    {
      "name": "CVE-2025-15599",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15599"
    },
    {
      "name": "CVE-2026-55379",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55379"
    },
    {
      "name": "CVE-2026-31488",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-31488"
    },
    {
      "name": "CVE-2026-9358",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9358"
    },
    {
      "name": "CVE-2026-44417",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44417"
    },
    {
      "name": "CVE-2026-14446",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14446"
    },
    {
      "name": "CVE-2026-54279",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54279"
    },
    {
      "name": "CVE-2026-33672",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33672"
    },
    {
      "name": "CVE-2026-6238",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6238"
    },
    {
      "name": "CVE-2026-8723",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8723"
    },
    {
      "name": "CVE-2026-75838",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75838"
    },
    {
      "name": "CVE-2026-59200",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59200"
    },
    {
      "name": "CVE-2025-58181",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-58181"
    },
    {
      "name": "CVE-2025-47914",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-47914"
    },
    {
      "name": "CVE-2026-59877",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59877"
    },
    {
      "name": "CVE-2026-9678",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9678"
    },
    {
      "name": "CVE-2026-39304",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39304"
    },
    {
      "name": "CVE-2026-48713",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48713"
    },
    {
      "name": "CVE-2026-49270",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49270"
    },
    {
      "name": "CVE-2026-34516",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34516"
    },
    {
      "name": "CVE-2026-46086",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46086"
    },
    {
      "name": "CVE-2026-15064",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15064"
    },
    {
      "name": "CVE-2026-42044",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42044"
    },
    {
      "name": "CVE-2026-14476",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14476"
    },
    {
      "name": "CVE-2026-53359",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53359"
    },
    {
      "name": "CVE-2026-16439",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16439"
    },
    {
      "name": "CVE-2018-16487",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-16487"
    },
    {
      "name": "CVE-2026-44728",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44728"
    },
    {
      "name": "CVE-2026-55955",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55955"
    },
    {
      "name": "CVE-2026-34517",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34517"
    },
    {
      "name": "CVE-2026-49477",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49477"
    },
    {
      "name": "CVE-2026-42034",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42034"
    },
    {
      "name": "CVE-2026-9322",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9322"
    },
    {
      "name": "CVE-2025-5889",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-5889"
    },
    {
      "name": "CVE-2026-31411",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-31411"
    },
    {
      "name": "CVE-2026-54513",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54513"
    },
    {
      "name": "CVE-2026-34591",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34591"
    },
    {
      "name": "CVE-2026-48779",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48779"
    },
    {
      "name": "CVE-2025-14914",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-14914"
    },
    {
      "name": "CVE-2026-9563",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9563"
    },
    {
      "name": "CVE-2026-13676",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13676"
    },
    {
      "name": "CVE-2026-54276",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54276"
    },
    {
      "name": "CVE-2026-53434",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53434"
    },
    {
      "name": "CVE-2026-40347",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40347"
    },
    {
      "name": "CVE-2026-43112",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43112"
    },
    {
      "name": "CVE-2025-66168",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-66168"
    },
    {
      "name": "CVE-2026-66142",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66142"
    },
    {
      "name": "CVE-2026-10051",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10051"
    },
    {
      "name": "CVE-2026-6322",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6322"
    },
    {
      "name": "CVE-2026-34513",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34513"
    },
    {
      "name": "CVE-2026-43869",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43869"
    },
    {
      "name": "CVE-2026-8400",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8400"
    },
    {
      "name": "CVE-2026-14980",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14980"
    },
    {
      "name": "CVE-2026-5078",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5078"
    },
    {
      "name": "CVE-2026-12143",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12143"
    },
    {
      "name": "CVE-2026-55655",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55655"
    },
    {
      "name": "CVE-2026-34514",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34514"
    },
    {
      "name": "CVE-2026-44431",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44431"
    },
    {
      "name": "CVE-2026-27601",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27601"
    },
    {
      "name": "CVE-2026-26996",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26996"
    },
    {
      "name": "CVE-2026-44486",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44486"
    },
    {
      "name": "CVE-2026-33227",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33227"
    },
    {
      "name": "CVE-2026-48775",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48775"
    },
    {
      "name": "CVE-2026-44496",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44496"
    },
    {
      "name": "CVE-2026-60081",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60081"
    },
    {
      "name": "CVE-2026-10879",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10879"
    },
    {
      "name": "CVE-2026-64530",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64530"
    },
    {
      "name": "CVE-2026-44492",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44492"
    },
    {
      "name": "CVE-2026-45736",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45736"
    },
    {
      "name": "CVE-2026-54225",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54225"
    },
    {
      "name": "CVE-2026-34520",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34520"
    },
    {
      "name": "CVE-2026-41238",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41238"
    },
    {
      "name": "CVE-2026-42037",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42037"
    },
    {
      "name": "CVE-2026-53404",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53404"
    },
    {
      "name": "CVE-2026-33416",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33416"
    },
    {
      "name": "CVE-2026-42042",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42042"
    },
    {
      "name": "CVE-2026-9071",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9071"
    },
    {
      "name": "CVE-2026-34993",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34993"
    },
    {
      "name": "CVE-2026-59198",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59198"
    },
    {
      "name": "CVE-2026-11806",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11806"
    },
    {
      "name": "CVE-2026-44294",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44294"
    },
    {
      "name": "CVE-2026-6321",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6321"
    },
    {
      "name": "CVE-2026-33231",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33231"
    },
    {
      "name": "CVE-2026-48801",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48801"
    },
    {
      "name": "CVE-2026-52923",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52923"
    },
    {
      "name": "CVE-2026-42012",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42012"
    },
    {
      "name": "CVE-2026-44490",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44490"
    },
    {
      "name": "CVE-2026-46917",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46917"
    },
    {
      "name": "CVE-2026-43116",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43116"
    },
    {
      "name": "CVE-2026-60147",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60147"
    },
    {
      "name": "CVE-2026-22815",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22815"
    },
    {
      "name": "CVE-2026-15280",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15280"
    },
    {
      "name": "CVE-2026-22008",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22008"
    },
    {
      "name": "CVE-2026-31802",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-31802"
    },
    {
      "name": "CVE-2026-56852",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56852"
    },
    {
      "name": "CVE-2026-6733",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6733"
    },
    {
      "name": "CVE-2026-13311",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13311"
    },
    {
      "name": "CVE-2026-44488",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44488"
    },
    {
      "name": "CVE-2026-33230",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33230"
    },
    {
      "name": "CVE-2026-10535",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10535"
    },
    {
      "name": "CVE-2026-34481",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34481"
    },
    {
      "name": "CVE-2025-47273",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-47273"
    },
    {
      "name": "CVE-2026-59204",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59204"
    },
    {
      "name": "CVE-2026-27904",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27904"
    },
    {
      "name": "CVE-2026-14474",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14474"
    },
    {
      "name": "CVE-2026-47059",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47059"
    },
    {
      "name": "CVE-2026-53539",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53539"
    },
    {
      "name": "CVE-2026-2739",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2739"
    },
    {
      "name": "CVE-2026-65898",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65898"
    },
    {
      "name": "CVE-2026-53917",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53917"
    },
    {
      "name": "CVE-2026-15392",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15392"
    },
    {
      "name": "CVE-2026-8177",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8177"
    }
  ],
  "initial_release_date": "2026-08-28T00:00:00",
  "last_revision_date": "2026-08-28T00:00:00",
  "links": [],
  "reference": "CERTFR-2026-AVI-1094",
  "revisions": [
    {
      "description": "Version initiale",
      "revision_date": "2026-08-28T00:00:00.000000"
    }
  ],
  "risks": [
    {
      "description": "D\u00e9ni de service \u00e0 distance"
    },
    {
      "description": "Injection de code indirecte \u00e0 distance (XSS)"
    },
    {
      "description": "Injection de requ\u00eates ill\u00e9gitimes par rebond (CSRF)"
    },
    {
      "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
    },
    {
      "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
    },
    {
      "description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
    },
    {
      "description": "Falsification de requ\u00eates c\u00f4t\u00e9 serveur (SSRF)"
    },
    {
      "description": "Contournement de la politique de s\u00e9curit\u00e9"
    },
    {
      "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
    },
    {
      "description": "\u00c9l\u00e9vation de privil\u00e8ges"
    }
  ],
  "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits IBM. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance, une \u00e9l\u00e9vation de privil\u00e8ges et un d\u00e9ni de service \u00e0 distance.",
  "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits IBM",
  "vendor_advisories": [
    {
      "published_at": "2026-08-27",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7285382",
      "url": "https://www.ibm.com/support/pages/node/7285382"
    },
    {
      "published_at": "2026-08-24",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7284666",
      "url": "https://www.ibm.com/support/pages/node/7284666"
    },
    {
      "published_at": "2026-08-28",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7285542",
      "url": "https://www.ibm.com/support/pages/node/7285542"
    },
    {
      "published_at": "2026-08-26",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7285272",
      "url": "https://www.ibm.com/support/pages/node/7285272"
    },
    {
      "published_at": "2026-08-26",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7285232",
      "url": "https://www.ibm.com/support/pages/node/7285232"
    },
    {
      "published_at": "2026-08-27",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7285472",
      "url": "https://www.ibm.com/support/pages/node/7285472"
    },
    {
      "published_at": "2026-08-26",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7285291",
      "url": "https://www.ibm.com/support/pages/node/7285291"
    },
    {
      "published_at": "2026-08-27",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7285470",
      "url": "https://www.ibm.com/support/pages/node/7285470"
    },
    {
      "published_at": "2026-08-27",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7285469",
      "url": "https://www.ibm.com/support/pages/node/7285469"
    },
    {
      "published_at": "2026-08-21",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7284528",
      "url": "https://www.ibm.com/support/pages/node/7284528"
    },
    {
      "published_at": "2026-08-27",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7285416",
      "url": "https://www.ibm.com/support/pages/node/7285416"
    },
    {
      "published_at": "2026-08-27",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7285376",
      "url": "https://www.ibm.com/support/pages/node/7285376"
    },
    {
      "published_at": "2026-08-27",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7285380",
      "url": "https://www.ibm.com/support/pages/node/7285380"
    },
    {
      "published_at": "2026-08-26",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7285275",
      "url": "https://www.ibm.com/support/pages/node/7285275"
    },
    {
      "published_at": "2026-08-26",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7285292",
      "url": "https://www.ibm.com/support/pages/node/7285292"
    },
    {
      "published_at": "2026-08-26",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7285234",
      "url": "https://www.ibm.com/support/pages/node/7285234"
    },
    {
      "published_at": "2026-08-26",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7285141",
      "url": "https://www.ibm.com/support/pages/node/7285141"
    },
    {
      "published_at": "2026-08-27",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7279466",
      "url": "https://www.ibm.com/support/pages/node/7279466"
    },
    {
      "published_at": "2026-08-24",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7284718",
      "url": "https://www.ibm.com/support/pages/node/7284718"
    },
    {
      "published_at": "2026-08-28",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7285509",
      "url": "https://www.ibm.com/support/pages/node/7285509"
    },
    {
      "published_at": "2026-08-27",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7285340",
      "url": "https://www.ibm.com/support/pages/node/7285340"
    },
    {
      "published_at": "2026-08-28",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7285513",
      "url": "https://www.ibm.com/support/pages/node/7285513"
    },
    {
      "published_at": "2026-08-27",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7285420",
      "url": "https://www.ibm.com/support/pages/node/7285420"
    },
    {
      "published_at": "2026-08-24",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7284710",
      "url": "https://www.ibm.com/support/pages/node/7284710"
    },
    {
      "published_at": "2026-08-26",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7285274",
      "url": "https://www.ibm.com/support/pages/node/7285274"
    },
    {
      "published_at": "2026-08-24",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7284653",
      "url": "https://www.ibm.com/support/pages/node/7284653"
    },
    {
      "published_at": "2026-08-27",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7285342",
      "url": "https://www.ibm.com/support/pages/node/7285342"
    },
    {
      "published_at": "2026-08-28",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7285539",
      "url": "https://www.ibm.com/support/pages/node/7285539"
    },
    {
      "published_at": "2026-08-24",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7284670",
      "url": "https://www.ibm.com/support/pages/node/7284670"
    },
    {
      "published_at": "2026-08-24",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7284806",
      "url": "https://www.ibm.com/support/pages/node/7284806"
    }
  ]
}

CERTFR-2026-AVI-1032
Vulnerability from certfr_avis

De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

Solutions

Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

Impacted products
Vendor Product Description
IBM WebSphere WebSphere Application Server versions 9.x antérieures à 9.0.5.29
IBM WebSphere WebSphere Application Server Liberty versions antérieures à 26.0.0.9
IBM QRadar QRadar App SDK versions antérieures à 2.2.6
IBM Db2 Db2 version 12.1 sans les derniers correctifs de sécurité
IBM Db2 Db2 versions 11.5 sans les derniers correctifs de sécurité
IBM WebSphere WebSphere eXtreme Scale versions 8.6.2.x antérieures à 8.6.2.2 et sans le correctif PH72363 iFix
IBM WebSphere WebSphere Service Registry and Repository Studio versions antérieures à V8.5.6.3_IJ59344
References
Bulletin de sécurité IBM 7283290 2026-08-11 vendor-advisory
Bulletin de sécurité IBM 7282872 2026-08-07 vendor-advisory
Bulletin de sécurité IBM 7283489 2026-08-12 vendor-advisory
Bulletin de sécurité IBM 7282868 2026-08-10 vendor-advisory
Bulletin de sécurité IBM 7283567 2026-08-12 vendor-advisory
Bulletin de sécurité IBM 7282947 2026-08-07 vendor-advisory
Bulletin de sécurité IBM 7282946 2026-08-07 vendor-advisory
Bulletin de sécurité IBM 7282949 2026-08-07 vendor-advisory
Bulletin de sécurité IBM 7277422 2026-08-12 vendor-advisory
Bulletin de sécurité IBM 7283488 2026-08-12 vendor-advisory
Bulletin de sécurité IBM 7279461 2026-08-07 vendor-advisory

Show details on source website


{
  "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
  "affected_systems": [
    {
      "description": "WebSphere Application Server versions 9.x ant\u00e9rieures \u00e0 9.0.5.29",
      "product": {
        "name": "WebSphere",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "WebSphere Application Server Liberty versions ant\u00e9rieures \u00e0 26.0.0.9",
      "product": {
        "name": "WebSphere",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "QRadar App SDK versions ant\u00e9rieures \u00e0 2.2.6",
      "product": {
        "name": "QRadar",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Db2 version 12.1 sans les derniers correctifs de s\u00e9curit\u00e9",
      "product": {
        "name": "Db2",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Db2 versions 11.5 sans les derniers correctifs de s\u00e9curit\u00e9",
      "product": {
        "name": "Db2",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "WebSphere eXtreme Scale versions 8.6.2.x ant\u00e9rieures \u00e0 8.6.2.2 et sans le correctif PH72363 iFix",
      "product": {
        "name": "WebSphere",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "WebSphere Service Registry and Repository Studio versions ant\u00e9rieures \u00e0 V8.5.6.3_IJ59344",
      "product": {
        "name": "WebSphere",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    }
  ],
  "affected_systems_content": "",
  "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
  "cves": [
    {
      "name": "CVE-2026-5588",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5588"
    },
    {
      "name": "CVE-2026-33871",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33871"
    },
    {
      "name": "CVE-2026-41254",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41254"
    },
    {
      "name": "CVE-2026-44405",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44405"
    },
    {
      "name": "CVE-2026-32990",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32990"
    },
    {
      "name": "CVE-2026-50645",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50645"
    },
    {
      "name": "CVE-2026-45416",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45416"
    },
    {
      "name": "CVE-2026-50560",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50560"
    },
    {
      "name": "CVE-2025-66614",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-66614"
    },
    {
      "name": "CVE-2026-33940",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33940"
    },
    {
      "name": "CVE-2026-44432",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44432"
    },
    {
      "name": "CVE-2026-16243",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16243"
    },
    {
      "name": "CVE-2026-9171",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9171"
    },
    {
      "name": "CVE-2026-47010",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47010"
    },
    {
      "name": "CVE-2026-11906",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11906"
    },
    {
      "name": "CVE-2026-22013",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22013"
    },
    {
      "name": "CVE-2026-47057",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47057"
    },
    {
      "name": "CVE-2026-29145",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-29145"
    },
    {
      "name": "CVE-2026-14525",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14525"
    },
    {
      "name": "CVE-2026-42580",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42580"
    },
    {
      "name": "CVE-2026-18499",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18499"
    },
    {
      "name": "CVE-2026-5516",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5516"
    },
    {
      "name": "CVE-2026-33870",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33870"
    },
    {
      "name": "CVE-2026-33941",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33941"
    },
    {
      "name": "CVE-2026-7246",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7246"
    },
    {
      "name": "CVE-2023-44487",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-44487"
    },
    {
      "name": "CVE-2026-42585",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42585"
    },
    {
      "name": "CVE-2026-11541",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11541"
    },
    {
      "name": "CVE-2026-11546",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11546"
    },
    {
      "name": "CVE-2021-23337",
      "url": "https://www.cve.org/CVERecord?id=CVE-2021-23337"
    },
    {
      "name": "CVE-2026-29146",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-29146"
    },
    {
      "name": "CVE-2026-10534",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10534"
    },
    {
      "name": "CVE-2026-10109",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10109"
    },
    {
      "name": "CVE-2026-45409",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45409"
    },
    {
      "name": "CVE-2026-25645",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25645"
    },
    {
      "name": "CVE-2026-4800",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4800"
    },
    {
      "name": "CVE-2026-42584",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42584"
    },
    {
      "name": "CVE-2026-4410",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4410"
    },
    {
      "name": "CVE-2026-45149",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45149"
    },
    {
      "name": "CVE-2026-5598",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5598"
    },
    {
      "name": "CVE-2026-9375",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9375"
    },
    {
      "name": "CVE-2026-34478",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34478"
    },
    {
      "name": "CVE-2026-35091",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35091"
    },
    {
      "name": "CVE-2026-8646",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8646"
    },
    {
      "name": "CVE-2026-34480",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34480"
    },
    {
      "name": "CVE-2026-33939",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33939"
    },
    {
      "name": "CVE-2026-9320",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9320"
    },
    {
      "name": "CVE-2026-9762",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9762"
    },
    {
      "name": "CVE-2025-68161",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68161"
    },
    {
      "name": "CVE-2026-34479",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34479"
    },
    {
      "name": "CVE-2026-47027",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47027"
    },
    {
      "name": "CVE-2026-47058",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47058"
    },
    {
      "name": "CVE-2026-16441",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16441"
    },
    {
      "name": "CVE-2026-9002",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9002"
    },
    {
      "name": "CVE-2025-66471",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-66471"
    },
    {
      "name": "CVE-2026-50020",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50020"
    },
    {
      "name": "CVE-2026-57819",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57819"
    },
    {
      "name": "CVE-2026-42578",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42578"
    },
    {
      "name": "CVE-2026-2950",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2950"
    },
    {
      "name": "CVE-2026-33916",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33916"
    },
    {
      "name": "CVE-2026-47063",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47063"
    },
    {
      "name": "CVE-2026-22021",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22021"
    },
    {
      "name": "CVE-2026-22007",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22007"
    },
    {
      "name": "CVE-2026-10543",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10543"
    },
    {
      "name": "CVE-2026-47021",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47021"
    },
    {
      "name": "CVE-2026-64958",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64958"
    },
    {
      "name": "CVE-2026-35092",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35092"
    },
    {
      "name": "CVE-2026-42583",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42583"
    },
    {
      "name": "CVE-2026-25854",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25854"
    },
    {
      "name": "CVE-2026-46968",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46968"
    },
    {
      "name": "CVE-2026-16956",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16956"
    },
    {
      "name": "CVE-2025-36372",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36372"
    },
    {
      "name": "CVE-2026-33937",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33937"
    },
    {
      "name": "CVE-2026-10695",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10695"
    },
    {
      "name": "CVE-2026-42581",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42581"
    },
    {
      "name": "CVE-2026-16439",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16439"
    },
    {
      "name": "CVE-2026-29129",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-29129"
    },
    {
      "name": "CVE-2026-11714",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11714"
    },
    {
      "name": "CVE-2026-41417",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41417"
    },
    {
      "name": "CVE-2026-48043",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48043"
    },
    {
      "name": "CVE-2026-9322",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9322"
    },
    {
      "name": "CVE-2026-42587",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42587"
    },
    {
      "name": "CVE-2026-9563",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9563"
    },
    {
      "name": "CVE-2026-47244",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47244"
    },
    {
      "name": "CVE-2026-7771",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7771"
    },
    {
      "name": "CVE-2026-8400",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8400"
    },
    {
      "name": "CVE-2026-12143",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12143"
    },
    {
      "name": "CVE-2026-44431",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44431"
    },
    {
      "name": "CVE-2024-3651",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-3651"
    },
    {
      "name": "CVE-2026-33938",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33938"
    },
    {
      "name": "CVE-2026-54225",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54225"
    },
    {
      "name": "CVE-2026-9071",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9071"
    },
    {
      "name": "CVE-2026-11806",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11806"
    },
    {
      "name": "CVE-2026-34477",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34477"
    },
    {
      "name": "CVE-2026-60147",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60147"
    },
    {
      "name": "CVE-2025-14813",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-14813"
    },
    {
      "name": "CVE-2025-13465",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-13465"
    },
    {
      "name": "CVE-2026-10535",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10535"
    },
    {
      "name": "CVE-2026-47059",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47059"
    }
  ],
  "initial_release_date": "2026-08-14T00:00:00",
  "last_revision_date": "2026-08-14T00:00:00",
  "links": [],
  "reference": "CERTFR-2026-AVI-1032",
  "revisions": [
    {
      "description": "Version initiale",
      "revision_date": "2026-08-14T00:00:00.000000"
    }
  ],
  "risks": [
    {
      "description": "D\u00e9ni de service \u00e0 distance"
    },
    {
      "description": "Injection de code indirecte \u00e0 distance (XSS)"
    },
    {
      "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
    },
    {
      "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
    },
    {
      "description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
    },
    {
      "description": "Falsification de requ\u00eates c\u00f4t\u00e9 serveur (SSRF)"
    },
    {
      "description": "Contournement de la politique de s\u00e9curit\u00e9"
    },
    {
      "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
    },
    {
      "description": "\u00c9l\u00e9vation de privil\u00e8ges"
    }
  ],
  "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits IBM. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance, une \u00e9l\u00e9vation de privil\u00e8ges et un d\u00e9ni de service \u00e0 distance.",
  "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits IBM",
  "vendor_advisories": [
    {
      "published_at": "2026-08-11",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7283290",
      "url": "https://www.ibm.com/support/pages/node/7283290"
    },
    {
      "published_at": "2026-08-07",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7282872",
      "url": "https://www.ibm.com/support/pages/node/7282872"
    },
    {
      "published_at": "2026-08-12",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7283489",
      "url": "https://www.ibm.com/support/pages/node/7283489"
    },
    {
      "published_at": "2026-08-10",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7282868",
      "url": "https://www.ibm.com/support/pages/node/7282868"
    },
    {
      "published_at": "2026-08-12",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7283567",
      "url": "https://www.ibm.com/support/pages/node/7283567"
    },
    {
      "published_at": "2026-08-07",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7282947",
      "url": "https://www.ibm.com/support/pages/node/7282947"
    },
    {
      "published_at": "2026-08-07",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7282946",
      "url": "https://www.ibm.com/support/pages/node/7282946"
    },
    {
      "published_at": "2026-08-07",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7282949",
      "url": "https://www.ibm.com/support/pages/node/7282949"
    },
    {
      "published_at": "2026-08-12",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7277422",
      "url": "https://www.ibm.com/support/pages/node/7277422"
    },
    {
      "published_at": "2026-08-12",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7283488",
      "url": "https://www.ibm.com/support/pages/node/7283488"
    },
    {
      "published_at": "2026-08-07",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7279461",
      "url": "https://www.ibm.com/support/pages/node/7279461"
    }
  ]
}

CERTFR-2026-AVI-0986
Vulnerability from certfr_avis

De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

Solutions

Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

Impacted products
Vendor Product Description
IBM WebSphere WebSphere Application Server version 9.0 avec IBM SDK, Java Technology Edition versions antérieures à 8 Service Refresh 8 FP70
IBM QRadar QRadar SIEM versions 7.5.x antérieures à 7.5.0 UP15 IF05 Hotfix 20260715231428
IBM WebSphere WebSphere Application Server version 8.5 avec IBM SDK, Java Technology Edition versions antérieures à 8 Service Refresh 8 FP70
IBM Informix Dynamic Server Informix Dynamic Server versions 15.0.x antérieures à 15.0.1.14
IBM QRadar QRadar SIEM versions 7.6.x antérieures à 7.6.0.2
IBM WebSphere WebSphere Automation versions 1.12.x antérieures à 1.13.0
IBM Sterling Sterling Control Center versions 6.4.2.0 antérieures à 6.4.2.0 iFix06
IBM Db2 Db2 Bridge versions antérieures à 1.1.5.1
IBM Informix Dynamic Server Informix Dynamic Server versions 14.10.x antérieures à 14.10.xC13W13
IBM WebSphere WebSphere Hybrid Edition versions 5.1 sans les derniers correctifs de sécurité
IBM WebSphere WebSphere Application Server - Liberty avec IBM SDK, Java Technology Edition versions antérieures à 8 SR8 FP70
IBM Tivoli Tivoli Composite Application Manager for Application Diagnostics version 7.1.0 sans les derniers correctifs de sécurité
IBM Sterling Sterling B2B Integrator et IBM Sterling File Gateway versions 6.2.2.x antérieures à B2Bi 6.2.2.1
IBM WebSphere WebSphere Service Registry and Repository version 8.5 sans les derniers correctifs de sécurité
IBM Sterling Sterling Order Management version 10.0.2604.2 sans le dernier correctif de sécurité
IBM Db2 Db2 Developer Extension versions 1.1.x antérieures à 1.1.2
IBM Sterling Sterling Control Center versions 6.3.1.0 antérieures à 6.3.1.0 iFix10
References
Bulletin de sécurité IBM 7282394 2026-08-03 vendor-advisory
Bulletin de sécurité IBM 7281616 2026-07-31 vendor-advisory
Bulletin de sécurité IBM 7281617 2026-07-31 vendor-advisory
Bulletin de sécurité IBM 7282084 2026-07-31 vendor-advisory
Bulletin de sécurité IBM 7282510 2026-08-04 vendor-advisory
Bulletin de sécurité IBM 7282066 2026-07-30 vendor-advisory
Bulletin de sécurité IBM 7282507 2026-08-04 vendor-advisory
Bulletin de sécurité IBM 7281615 2026-07-31 vendor-advisory
Bulletin de sécurité IBM 7282664 2026-08-05 vendor-advisory
Bulletin de sécurité IBM 7282502 2026-08-04 vendor-advisory
Bulletin de sécurité IBM 7282666 2026-08-05 vendor-advisory
Bulletin de sécurité IBM 7282496 2026-08-04 vendor-advisory
Bulletin de sécurité IBM 7282665 2026-08-05 vendor-advisory
Bulletin de sécurité IBM 7282528 2026-08-04 vendor-advisory
Bulletin de sécurité IBM 7282820 2026-08-07 vendor-advisory
Bulletin de sécurité IBM 7282527 2026-08-04 vendor-advisory
Bulletin de sécurité IBM 7282322 2026-08-02 vendor-advisory
Bulletin de sécurité IBM 7282618 2026-08-05 vendor-advisory
Bulletin de sécurité IBM 7282514 2026-08-04 vendor-advisory
Bulletin de sécurité IBM 7282446 2026-08-04 vendor-advisory
Bulletin de sécurité IBM 7282827 2026-08-07 vendor-advisory
Bulletin de sécurité IBM 7282080 2026-07-31 vendor-advisory
Bulletin de sécurité IBM 7282819 2026-08-07 vendor-advisory
Bulletin de sécurité IBM 7282829 2026-08-07 vendor-advisory
Bulletin de sécurité IBM 7282505 2026-08-04 vendor-advisory
Bulletin de sécurité IBM 7282667 2026-08-05 vendor-advisory
Bulletin de sécurité IBM 7282495 2026-08-04 vendor-advisory
Bulletin de sécurité IBM 7282523 2026-08-04 vendor-advisory
Bulletin de sécurité IBM 7282822 2026-08-07 vendor-advisory
Bulletin de sécurité IBM 7282447 2026-08-04 vendor-advisory
Bulletin de sécurité IBM 7282821 2026-08-07 vendor-advisory
Bulletin de sécurité IBM 7282588 2026-08-05 vendor-advisory
Bulletin de sécurité IBM 7282606 2026-08-05 vendor-advisory
Bulletin de sécurité IBM 7282279 2026-07-31 vendor-advisory

Show details on source website


{
  "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
  "affected_systems": [
    {
      "description": "WebSphere Application Server version 9.0 avec IBM SDK, Java Technology Edition versions ant\u00e9rieures \u00e0 8 Service Refresh 8 FP70 ",
      "product": {
        "name": "WebSphere",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "QRadar SIEM versions 7.5.x ant\u00e9rieures \u00e0 7.5.0 UP15 IF05 Hotfix 20260715231428",
      "product": {
        "name": "QRadar",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "WebSphere Application Server version 8.5 avec IBM SDK, Java Technology Edition versions ant\u00e9rieures \u00e0 8 Service Refresh 8 FP70 ",
      "product": {
        "name": "WebSphere",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Informix Dynamic Server versions 15.0.x ant\u00e9rieures \u00e0 15.0.1.14",
      "product": {
        "name": "Informix Dynamic Server",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "QRadar SIEM versions 7.6.x ant\u00e9rieures \u00e0 7.6.0.2",
      "product": {
        "name": "QRadar",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "WebSphere Automation versions 1.12.x ant\u00e9rieures \u00e0 1.13.0",
      "product": {
        "name": "WebSphere",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Sterling Control Center versions 6.4.2.0 ant\u00e9rieures \u00e0 6.4.2.0 iFix06",
      "product": {
        "name": "Sterling",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Db2 Bridge versions ant\u00e9rieures \u00e0 1.1.5.1",
      "product": {
        "name": "Db2",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Informix Dynamic Server versions 14.10.x ant\u00e9rieures \u00e0 14.10.xC13W13",
      "product": {
        "name": "Informix Dynamic Server",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "WebSphere Hybrid Edition versions 5.1 sans les derniers correctifs de s\u00e9curit\u00e9",
      "product": {
        "name": "WebSphere",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "WebSphere Application Server - Liberty avec IBM SDK, Java Technology Edition versions ant\u00e9rieures \u00e0 8 SR8 FP70 ",
      "product": {
        "name": "WebSphere",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Tivoli Composite Application Manager for Application Diagnostics version 7.1.0 sans les derniers correctifs de s\u00e9curit\u00e9",
      "product": {
        "name": "Tivoli",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Sterling B2B Integrator et IBM Sterling File Gateway versions 6.2.2.x ant\u00e9rieures \u00e0 B2Bi 6.2.2.1",
      "product": {
        "name": "Sterling",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "WebSphere Service Registry and Repository version 8.5 sans les derniers correctifs de s\u00e9curit\u00e9",
      "product": {
        "name": "WebSphere",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Sterling Order Management version 10.0.2604.2 sans le dernier correctif de s\u00e9curit\u00e9",
      "product": {
        "name": "Sterling",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Db2 Developer Extension versions 1.1.x ant\u00e9rieures \u00e0 1.1.2",
      "product": {
        "name": "Db2",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Sterling Control Center versions 6.3.1.0 ant\u00e9rieures \u00e0 6.3.1.0 iFix10",
      "product": {
        "name": "Sterling",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    }
  ],
  "affected_systems_content": "",
  "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
  "cves": [
    {
      "name": "CVE-2026-5588",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5588"
    },
    {
      "name": "CVE-2026-33871",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33871"
    },
    {
      "name": "CVE-2026-41254",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41254"
    },
    {
      "name": "CVE-2026-50645",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50645"
    },
    {
      "name": "CVE-2026-45852",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45852"
    },
    {
      "name": "CVE-2026-43515",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43515"
    },
    {
      "name": "CVE-2026-31685",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-31685"
    },
    {
      "name": "CVE-2026-16184",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16184"
    },
    {
      "name": "CVE-2026-15328",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15328"
    },
    {
      "name": "CVE-2026-42496",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42496"
    },
    {
      "name": "CVE-2026-8201",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8201"
    },
    {
      "name": "CVE-2026-54514",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54514"
    },
    {
      "name": "CVE-2026-4893",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4893"
    },
    {
      "name": "CVE-2026-42497",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42497"
    },
    {
      "name": "CVE-2026-54399",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54399"
    },
    {
      "name": "CVE-2026-16243",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16243"
    },
    {
      "name": "CVE-2026-9171",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9171"
    },
    {
      "name": "CVE-2026-47010",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47010"
    },
    {
      "name": "CVE-2026-31787",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-31787"
    },
    {
      "name": "CVE-2026-31613",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-31613"
    },
    {
      "name": "CVE-2026-43163",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43163"
    },
    {
      "name": "CVE-2026-11906",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11906"
    },
    {
      "name": "CVE-2026-31581",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-31581"
    },
    {
      "name": "CVE-2026-22013",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22013"
    },
    {
      "name": "CVE-2026-47057",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47057"
    },
    {
      "name": "CVE-2026-42580",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42580"
    },
    {
      "name": "CVE-2026-4892",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4892"
    },
    {
      "name": "CVE-2026-14528",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14528"
    },
    {
      "name": "CVE-2025-68347",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68347"
    },
    {
      "name": "CVE-2026-8200",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8200"
    },
    {
      "name": "CVE-2026-6914",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6914"
    },
    {
      "name": "CVE-2026-50163",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50163"
    },
    {
      "name": "CVE-2026-54516",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54516"
    },
    {
      "name": "CVE-2026-54515",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54515"
    },
    {
      "name": "CVE-2026-31408",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-31408"
    },
    {
      "name": "CVE-2026-33870",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33870"
    },
    {
      "name": "CVE-2026-4890",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4890"
    },
    {
      "name": "CVE-2026-42585",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42585"
    },
    {
      "name": "CVE-2026-13476",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13476"
    },
    {
      "name": "CVE-2026-10025",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10025"
    },
    {
      "name": "CVE-2026-42959",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42959"
    },
    {
      "name": "CVE-2026-54475",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54475"
    },
    {
      "name": "CVE-2026-31786",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-31786"
    },
    {
      "name": "CVE-2026-6915",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6915"
    },
    {
      "name": "CVE-2026-53916",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53916"
    },
    {
      "name": "CVE-2026-2291",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2291"
    },
    {
      "name": "CVE-2026-15057",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15057"
    },
    {
      "name": "CVE-2026-10109",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10109"
    },
    {
      "name": "CVE-2025-13755",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-13755"
    },
    {
      "name": "CVE-2026-42584",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42584"
    },
    {
      "name": "CVE-2026-41284",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41284"
    },
    {
      "name": "CVE-2026-45186",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45186"
    },
    {
      "name": "CVE-2026-48978",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48978"
    },
    {
      "name": "CVE-2026-6051",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6051"
    },
    {
      "name": "CVE-2026-15325",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15325"
    },
    {
      "name": "CVE-2023-53781",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-53781"
    },
    {
      "name": "CVE-2026-49268",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49268"
    },
    {
      "name": "CVE-2026-14976",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14976"
    },
    {
      "name": "CVE-2026-5598",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5598"
    },
    {
      "name": "CVE-2026-23270",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23270"
    },
    {
      "name": "CVE-2026-43618",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43618"
    },
    {
      "name": "CVE-2026-14512",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14512"
    },
    {
      "name": "CVE-2026-46181",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46181"
    },
    {
      "name": "CVE-2026-10842",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10842"
    },
    {
      "name": "CVE-2026-34478",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34478"
    },
    {
      "name": "CVE-2026-54428",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54428"
    },
    {
      "name": "CVE-2026-50162",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50162"
    },
    {
      "name": "CVE-2026-34480",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34480"
    },
    {
      "name": "CVE-2025-39981",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-39981"
    },
    {
      "name": "CVE-2026-46243",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46243"
    },
    {
      "name": "CVE-2026-31684",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-31684"
    },
    {
      "name": "CVE-2026-6053",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6053"
    },
    {
      "name": "CVE-2025-68183",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68183"
    },
    {
      "name": "CVE-2026-9762",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9762"
    },
    {
      "name": "CVE-2026-43051",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43051"
    },
    {
      "name": "CVE-2026-50734",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50734"
    },
    {
      "name": "CVE-2026-48962",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48962"
    },
    {
      "name": "CVE-2025-68161",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68161"
    },
    {
      "name": "CVE-2026-14974",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14974"
    },
    {
      "name": "CVE-2026-34479",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34479"
    },
    {
      "name": "CVE-2026-31669",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-31669"
    },
    {
      "name": "CVE-2026-47027",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47027"
    },
    {
      "name": "CVE-2026-47058",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47058"
    },
    {
      "name": "CVE-2026-16441",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16441"
    },
    {
      "name": "CVE-2026-6052",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6052"
    },
    {
      "name": "CVE-2026-8053",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8053"
    },
    {
      "name": "CVE-2026-14981",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14981"
    },
    {
      "name": "CVE-2026-45447",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45447"
    },
    {
      "name": "CVE-2026-22990",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22990"
    },
    {
      "name": "CVE-2026-39979",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39979"
    },
    {
      "name": "CVE-2026-14529",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14529"
    },
    {
      "name": "CVE-2026-8199",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8199"
    },
    {
      "name": "CVE-2026-54512",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54512"
    },
    {
      "name": "CVE-2026-43158",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43158"
    },
    {
      "name": "CVE-2026-23243",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23243"
    },
    {
      "name": "CVE-2026-43514",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43514"
    },
    {
      "name": "CVE-2026-40164",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40164"
    },
    {
      "name": "CVE-2026-16192",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16192"
    },
    {
      "name": "CVE-2026-47063",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47063"
    },
    {
      "name": "CVE-2024-34459",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-34459"
    },
    {
      "name": "CVE-2026-14515",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14515"
    },
    {
      "name": "CVE-2026-23392",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23392"
    },
    {
      "name": "CVE-2026-22021",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22021"
    },
    {
      "name": "CVE-2026-46125",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46125"
    },
    {
      "name": "CVE-2026-46152",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46152"
    },
    {
      "name": "CVE-2026-5946",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5946"
    },
    {
      "name": "CVE-2026-22007",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22007"
    },
    {
      "name": "CVE-2026-47021",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47021"
    },
    {
      "name": "CVE-2026-49434",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49434"
    },
    {
      "name": "CVE-2026-43020",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43020"
    },
    {
      "name": "CVE-2026-29518",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-29518"
    },
    {
      "name": "CVE-2026-2482",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2482"
    },
    {
      "name": "CVE-2026-11897",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11897"
    },
    {
      "name": "CVE-2026-42583",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42583"
    },
    {
      "name": "CVE-2026-49432",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49432"
    },
    {
      "name": "CVE-2026-46968",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46968"
    },
    {
      "name": "CVE-2026-28390",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28390"
    },
    {
      "name": "CVE-2026-6893",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6893"
    },
    {
      "name": "CVE-2025-71116",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71116"
    },
    {
      "name": "CVE-2025-36372",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36372"
    },
    {
      "name": "CVE-2026-31532",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-31532"
    },
    {
      "name": "CVE-2026-14446",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14446"
    },
    {
      "name": "CVE-2026-10695",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10695"
    },
    {
      "name": "CVE-2026-43190",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43190"
    },
    {
      "name": "CVE-2026-42581",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42581"
    },
    {
      "name": "CVE-2026-46056",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46056"
    },
    {
      "name": "CVE-2026-43513",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43513"
    },
    {
      "name": "CVE-2026-31709",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-31709"
    },
    {
      "name": "CVE-2026-54517",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54517"
    },
    {
      "name": "CVE-2026-15064",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15064"
    },
    {
      "name": "CVE-2026-23455",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23455"
    },
    {
      "name": "CVE-2026-16439",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16439"
    },
    {
      "name": "CVE-2025-68366",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68366"
    },
    {
      "name": "CVE-2026-43110",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43110"
    },
    {
      "name": "CVE-2026-3039",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3039"
    },
    {
      "name": "CVE-2026-41417",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41417"
    },
    {
      "name": "CVE-2026-9322",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9322"
    },
    {
      "name": "CVE-2026-3012",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3012"
    },
    {
      "name": "CVE-2026-42587",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42587"
    },
    {
      "name": "CVE-2026-54513",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54513"
    },
    {
      "name": "CVE-2026-22984",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22984"
    },
    {
      "name": "CVE-2026-43037",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43037"
    },
    {
      "name": "CVE-2026-54518",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54518"
    },
    {
      "name": "CVE-2025-53906",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-53906"
    },
    {
      "name": "CVE-2024-4741",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-4741"
    },
    {
      "name": "CVE-2026-6938",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6938"
    },
    {
      "name": "CVE-2026-7771",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7771"
    },
    {
      "name": "CVE-2026-8400",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8400"
    },
    {
      "name": "CVE-2026-14980",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14980"
    },
    {
      "name": "CVE-2026-9538",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9538"
    },
    {
      "name": "CVE-2026-4480",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4480"
    },
    {
      "name": "CVE-2025-21858",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-21858"
    },
    {
      "name": "CVE-2026-43027",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43027"
    },
    {
      "name": "CVE-2026-50151",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50151"
    },
    {
      "name": "CVE-2026-43964",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43964"
    },
    {
      "name": "CVE-2026-35177",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35177"
    },
    {
      "name": "CVE-2026-43125",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43125"
    },
    {
      "name": "CVE-2026-43512",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43512"
    },
    {
      "name": "CVE-2026-13367",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13367"
    },
    {
      "name": "CVE-2026-42498",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42498"
    },
    {
      "name": "CVE-2026-4891",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4891"
    },
    {
      "name": "CVE-2026-4408",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4408"
    },
    {
      "name": "CVE-2026-34477",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34477"
    },
    {
      "name": "CVE-2026-8202",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8202"
    },
    {
      "name": "CVE-2026-4046",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4046"
    },
    {
      "name": "CVE-2026-60147",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60147"
    },
    {
      "name": "CVE-2026-43329",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43329"
    },
    {
      "name": "CVE-2026-15280",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15280"
    },
    {
      "name": "CVE-2026-42944",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42944"
    },
    {
      "name": "CVE-2026-43038",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43038"
    },
    {
      "name": "CVE-2025-14813",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-14813"
    },
    {
      "name": "CVE-2026-10535",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10535"
    },
    {
      "name": "CVE-2026-1718",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1718"
    },
    {
      "name": "CVE-2026-47059",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47059"
    },
    {
      "name": "CVE-2026-41293",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41293"
    },
    {
      "name": "CVE-2026-53917",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53917"
    }
  ],
  "initial_release_date": "2026-08-07T00:00:00",
  "last_revision_date": "2026-08-07T00:00:00",
  "links": [],
  "reference": "CERTFR-2026-AVI-0986",
  "revisions": [
    {
      "description": "Version initiale",
      "revision_date": "2026-08-07T00:00:00.000000"
    }
  ],
  "risks": [
    {
      "description": "D\u00e9ni de service \u00e0 distance"
    },
    {
      "description": "Injection de code indirecte \u00e0 distance (XSS)"
    },
    {
      "description": "Injection de requ\u00eates ill\u00e9gitimes par rebond (CSRF)"
    },
    {
      "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
    },
    {
      "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
    },
    {
      "description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
    },
    {
      "description": "Falsification de requ\u00eates c\u00f4t\u00e9 serveur (SSRF)"
    },
    {
      "description": "Contournement de la politique de s\u00e9curit\u00e9"
    },
    {
      "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
    },
    {
      "description": "\u00c9l\u00e9vation de privil\u00e8ges"
    }
  ],
  "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits IBM. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance, une \u00e9l\u00e9vation de privil\u00e8ges et un d\u00e9ni de service \u00e0 distance.",
  "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits IBM",
  "vendor_advisories": [
    {
      "published_at": "2026-08-03",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7282394",
      "url": "https://www.ibm.com/support/pages/node/7282394"
    },
    {
      "published_at": "2026-07-31",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7281616",
      "url": "https://www.ibm.com/support/pages/node/7281616"
    },
    {
      "published_at": "2026-07-31",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7281617",
      "url": "https://www.ibm.com/support/pages/node/7281617"
    },
    {
      "published_at": "2026-07-31",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7282084",
      "url": "https://www.ibm.com/support/pages/node/7282084"
    },
    {
      "published_at": "2026-08-04",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7282510",
      "url": "https://www.ibm.com/support/pages/node/7282510"
    },
    {
      "published_at": "2026-07-30",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7282066",
      "url": "https://www.ibm.com/support/pages/node/7282066"
    },
    {
      "published_at": "2026-08-04",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7282507",
      "url": "https://www.ibm.com/support/pages/node/7282507"
    },
    {
      "published_at": "2026-07-31",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7281615",
      "url": "https://www.ibm.com/support/pages/node/7281615"
    },
    {
      "published_at": "2026-08-05",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7282664",
      "url": "https://www.ibm.com/support/pages/node/7282664"
    },
    {
      "published_at": "2026-08-04",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7282502",
      "url": "https://www.ibm.com/support/pages/node/7282502"
    },
    {
      "published_at": "2026-08-05",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7282666",
      "url": "https://www.ibm.com/support/pages/node/7282666"
    },
    {
      "published_at": "2026-08-04",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7282496",
      "url": "https://www.ibm.com/support/pages/node/7282496"
    },
    {
      "published_at": "2026-08-05",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7282665",
      "url": "https://www.ibm.com/support/pages/node/7282665"
    },
    {
      "published_at": "2026-08-04",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7282528",
      "url": "https://www.ibm.com/support/pages/node/7282528"
    },
    {
      "published_at": "2026-08-07",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7282820",
      "url": "https://www.ibm.com/support/pages/node/7282820"
    },
    {
      "published_at": "2026-08-04",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7282527",
      "url": "https://www.ibm.com/support/pages/node/7282527"
    },
    {
      "published_at": "2026-08-02",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7282322",
      "url": "https://www.ibm.com/support/pages/node/7282322"
    },
    {
      "published_at": "2026-08-05",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7282618",
      "url": "https://www.ibm.com/support/pages/node/7282618"
    },
    {
      "published_at": "2026-08-04",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7282514",
      "url": "https://www.ibm.com/support/pages/node/7282514"
    },
    {
      "published_at": "2026-08-04",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7282446",
      "url": "https://www.ibm.com/support/pages/node/7282446"
    },
    {
      "published_at": "2026-08-07",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7282827",
      "url": "https://www.ibm.com/support/pages/node/7282827"
    },
    {
      "published_at": "2026-07-31",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7282080",
      "url": "https://www.ibm.com/support/pages/node/7282080"
    },
    {
      "published_at": "2026-08-07",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7282819",
      "url": "https://www.ibm.com/support/pages/node/7282819"
    },
    {
      "published_at": "2026-08-07",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7282829",
      "url": "https://www.ibm.com/support/pages/node/7282829"
    },
    {
      "published_at": "2026-08-04",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7282505",
      "url": "https://www.ibm.com/support/pages/node/7282505"
    },
    {
      "published_at": "2026-08-05",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7282667",
      "url": "https://www.ibm.com/support/pages/node/7282667"
    },
    {
      "published_at": "2026-08-04",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7282495",
      "url": "https://www.ibm.com/support/pages/node/7282495"
    },
    {
      "published_at": "2026-08-04",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7282523",
      "url": "https://www.ibm.com/support/pages/node/7282523"
    },
    {
      "published_at": "2026-08-07",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7282822",
      "url": "https://www.ibm.com/support/pages/node/7282822"
    },
    {
      "published_at": "2026-08-04",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7282447",
      "url": "https://www.ibm.com/support/pages/node/7282447"
    },
    {
      "published_at": "2026-08-07",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7282821",
      "url": "https://www.ibm.com/support/pages/node/7282821"
    },
    {
      "published_at": "2026-08-05",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7282588",
      "url": "https://www.ibm.com/support/pages/node/7282588"
    },
    {
      "published_at": "2026-08-05",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7282606",
      "url": "https://www.ibm.com/support/pages/node/7282606"
    },
    {
      "published_at": "2026-07-31",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7282279",
      "url": "https://www.ibm.com/support/pages/node/7282279"
    }
  ]
}

CERTFR-2026-AVI-0958
Vulnerability from certfr_avis

De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

Solutions

Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

Impacted products
Vendor Product Description
IBM Db2 Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions v4.8 à v5.3.x antérieures à v5.4 patch 3
IBM AIX AIX versions 7.3.x sans le correctif de sécurité curl_fix11.tar
IBM QRadar QRadar Data Synchronization App versions antérieures à 4.0.0
IBM QRadar QRadar Pulse App versions antérieures à 2.2.17
IBM WebSphere Application Server WebSphere Application Server versions 9.0.x sans les correctifs de sécurité temporaires antérieures à 9.0.5.29 (disponibilité prévue pour le troisième trimestre 2026)
IBM Sterling Control Center Sterling Control Center versions 6.3.1.0 sans le correctif iFix10
IBM WebSphere Application Server WebSphere Application Server versions 8.5.x sans les correctifs de sécurité temporaires antérieures à 8.5.5.31 (disponibilité prévue pour le troisième trimestre 2026)
IBM Sterling Control Center Sterling Control Center versions 6.4.2.0 sans le correctif iFix05
IBM Sterling Sterling External Authentication Server versions 6.1.x antérieures à 6.1.1.4 GA
IBM QRadar QRadar SIEM versions 7.5.x antérieures à 7.5.0 UP15 IF05
IBM Sterling B2B Integrator Sterling B2B Integrator et Sterling File Gateway versions 6.2.0.x antérieures à 6.2.0.6_1
IBM Sterling B2B Integrator Sterling B2B Integrator et Sterling File Gateway versions 6.2.1.x antérieures à 6.2.1.2
IBM Sterling Control Center Sterling Control Center versions 6.4.1.0 sans le correctif iFix04
IBM Sterling B2B Integrator Sterling B2B Integrator et Sterling File Gateway versions 6.2.2.x antérieures à 6.2.2.1
IBM WebSphere Application Server WebSphere Application Server Liberty versions antérieures à 26.0.0.9 (disponibilité prévue pour le troisième trimestre 2026)
References
Bulletin de sécurité IBM 7281450 2026-07-27 vendor-advisory
Bulletin de sécurité IBM 7281625 2026-07-28 vendor-advisory
Bulletin de sécurité IBM 7281949 2026-07-30 vendor-advisory
Bulletin de sécurité IBM 7277692 2026-07-27 vendor-advisory
Bulletin de sécurité IBM 7281628 2026-07-28 vendor-advisory
Bulletin de sécurité IBM 7281135 2026-07-24 vendor-advisory
Bulletin de sécurité IBM 7281375 2026-07-27 vendor-advisory
Bulletin de sécurité IBM 7281743 2026-07-29 vendor-advisory
Bulletin de sécurité IBM 7281373 2026-07-27 vendor-advisory
Bulletin de sécurité IBM 7281388 2026-07-27 vendor-advisory
Bulletin de sécurité IBM 7281721 2026-07-28 vendor-advisory
Bulletin de sécurité IBM 7281369 2026-07-27 vendor-advisory
Bulletin de sécurité IBM 7281648 2026-07-28 vendor-advisory
Bulletin de sécurité IBM 7281374 2026-07-27 vendor-advisory
Bulletin de sécurité IBM 7281136 2026-07-24 vendor-advisory
Bulletin de sécurité IBM 7281641 2026-07-28 vendor-advisory
Bulletin de sécurité IBM 7281631 2026-07-28 vendor-advisory
Bulletin de sécurité IBM 7281371 2026-07-27 vendor-advisory
Bulletin de sécurité IBM 7281633 2026-07-28 vendor-advisory
Bulletin de sécurité IBM 7281438 2026-07-27 vendor-advisory
Bulletin de sécurité IBM 7281370 2026-07-27 vendor-advisory
Bulletin de sécurité IBM 7281565 2026-07-27 vendor-advisory
Bulletin de sécurité IBM 7281368 2026-07-27 vendor-advisory
Bulletin de sécurité IBM 7281350 2026-07-27 vendor-advisory
Bulletin de sécurité IBM 7281651 2026-07-28 vendor-advisory
Bulletin de sécurité IBM 7281950 2026-07-30 vendor-advisory
Bulletin de sécurité IBM 7281567 2026-07-27 vendor-advisory
Bulletin de sécurité IBM 7280950 2026-07-23 vendor-advisory
Bulletin de sécurité IBM 7281441 2026-07-27 vendor-advisory
Bulletin de sécurité IBM 7281649 2026-07-28 vendor-advisory

Show details on source website


{
  "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
  "affected_systems": [
    {
      "description": "Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions v4.8 \u00e0 v5.3.x ant\u00e9rieures \u00e0 v5.4 patch 3",
      "product": {
        "name": "Db2",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "AIX versions 7.3.x sans le correctif de s\u00e9curit\u00e9 curl_fix11.tar",
      "product": {
        "name": "AIX",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "QRadar Data Synchronization App versions ant\u00e9rieures \u00e0 4.0.0",
      "product": {
        "name": "QRadar",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "QRadar Pulse App versions ant\u00e9rieures \u00e0 2.2.17",
      "product": {
        "name": "QRadar",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "WebSphere Application Server versions 9.0.x sans les correctifs de s\u00e9curit\u00e9 temporaires ant\u00e9rieures \u00e0 9.0.5.29 (disponibilit\u00e9 pr\u00e9vue pour le troisi\u00e8me trimestre 2026)",
      "product": {
        "name": "WebSphere Application Server",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Sterling Control Center versions 6.3.1.0 sans le correctif iFix10",
      "product": {
        "name": "Sterling Control Center",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "WebSphere Application Server versions 8.5.x sans les correctifs de s\u00e9curit\u00e9 temporaires ant\u00e9rieures \u00e0 8.5.5.31 (disponibilit\u00e9 pr\u00e9vue pour le troisi\u00e8me trimestre 2026)",
      "product": {
        "name": "WebSphere Application Server",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Sterling Control Center versions 6.4.2.0 sans le correctif iFix05",
      "product": {
        "name": "Sterling Control Center",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Sterling External Authentication Server versions 6.1.x ant\u00e9rieures \u00e0 6.1.1.4 GA",
      "product": {
        "name": "Sterling",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "QRadar SIEM versions 7.5.x ant\u00e9rieures \u00e0 7.5.0 UP15 IF05",
      "product": {
        "name": "QRadar",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Sterling B2B Integrator et Sterling File Gateway versions 6.2.0.x ant\u00e9rieures \u00e0 6.2.0.6_1",
      "product": {
        "name": "Sterling B2B Integrator",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Sterling B2B Integrator et Sterling File Gateway versions 6.2.1.x ant\u00e9rieures \u00e0 6.2.1.2",
      "product": {
        "name": "Sterling B2B Integrator",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Sterling Control Center versions 6.4.1.0 sans le correctif iFix04",
      "product": {
        "name": "Sterling Control Center",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Sterling B2B Integrator et Sterling File Gateway versions 6.2.2.x ant\u00e9rieures \u00e0 6.2.2.1",
      "product": {
        "name": "Sterling B2B Integrator",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "WebSphere Application Server Liberty versions ant\u00e9rieures \u00e0 26.0.0.9 (disponibilit\u00e9 pr\u00e9vue pour le troisi\u00e8me trimestre 2026)",
      "product": {
        "name": "WebSphere Application Server",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    }
  ],
  "affected_systems_content": "",
  "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
  "cves": [
    {
      "name": "CVE-2026-5588",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5588"
    },
    {
      "name": "CVE-2026-45505",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45505"
    },
    {
      "name": "CVE-2025-66199",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-66199"
    },
    {
      "name": "CVE-2026-3449",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3449"
    },
    {
      "name": "CVE-2026-59871",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59871"
    },
    {
      "name": "CVE-2026-42588",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42588"
    },
    {
      "name": "CVE-2026-33845",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33845"
    },
    {
      "name": "CVE-2026-44025",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44025"
    },
    {
      "name": "CVE-2026-42253",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42253"
    },
    {
      "name": "CVE-2026-39830",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39830"
    },
    {
      "name": "CVE-2026-42041",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42041"
    },
    {
      "name": "CVE-2026-42508",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42508"
    },
    {
      "name": "CVE-2026-41716",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41716"
    },
    {
      "name": "CVE-2026-16184",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16184"
    },
    {
      "name": "CVE-2026-15328",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15328"
    },
    {
      "name": "CVE-2025-15469",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15469"
    },
    {
      "name": "CVE-2020-13956",
      "url": "https://www.cve.org/CVERecord?id=CVE-2020-13956"
    },
    {
      "name": "CVE-2025-47944",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-47944"
    },
    {
      "name": "CVE-2025-56200",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-56200"
    },
    {
      "name": "CVE-2026-59874",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59874"
    },
    {
      "name": "CVE-2026-42258",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42258"
    },
    {
      "name": "CVE-2026-7769",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7769"
    },
    {
      "name": "CVE-2026-30827",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30827"
    },
    {
      "name": "CVE-2026-22752",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22752"
    },
    {
      "name": "CVE-2026-39833",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39833"
    },
    {
      "name": "CVE-2025-22228",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-22228"
    },
    {
      "name": "CVE-2026-8458",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8458"
    },
    {
      "name": "CVE-2026-2391",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2391"
    },
    {
      "name": "CVE-2026-1605",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1605"
    },
    {
      "name": "CVE-2026-46605",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46605"
    },
    {
      "name": "CVE-2026-22013",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22013"
    },
    {
      "name": "CVE-2026-53655",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53655"
    },
    {
      "name": "CVE-2026-29145",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-29145"
    },
    {
      "name": "CVE-2026-22018",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22018"
    },
    {
      "name": "CVE-2026-39832",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39832"
    },
    {
      "name": "CVE-2020-13955",
      "url": "https://www.cve.org/CVERecord?id=CVE-2020-13955"
    },
    {
      "name": "CVE-2026-39829",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39829"
    },
    {
      "name": "CVE-2026-41988",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41988"
    },
    {
      "name": "CVE-2026-14528",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14528"
    },
    {
      "name": "CVE-2026-6357",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6357"
    },
    {
      "name": "CVE-2026-23745",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23745"
    },
    {
      "name": "CVE-2026-2006",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2006"
    },
    {
      "name": "CVE-2026-53550",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53550"
    },
    {
      "name": "CVE-2026-41721",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41721"
    },
    {
      "name": "CVE-2026-54905",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54905"
    },
    {
      "name": "CVE-2026-0994",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0994"
    },
    {
      "name": "CVE-2026-49157",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49157"
    },
    {
      "name": "CVE-2021-47154",
      "url": "https://www.cve.org/CVERecord?id=CVE-2021-47154"
    },
    {
      "name": "CVE-2026-44494",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44494"
    },
    {
      "name": "CVE-2026-54899",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54899"
    },
    {
      "name": "CVE-2026-39834",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39834"
    },
    {
      "name": "CVE-2025-15284",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15284"
    },
    {
      "name": "CVE-2026-41635",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41635"
    },
    {
      "name": "CVE-2026-46595",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46595"
    },
    {
      "name": "CVE-2026-54901",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54901"
    },
    {
      "name": "CVE-2026-42036",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42036"
    },
    {
      "name": "CVE-2026-2005",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2005"
    },
    {
      "name": "CVE-2022-39135",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-39135"
    },
    {
      "name": "CVE-2026-39821",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39821"
    },
    {
      "name": "CVE-2026-33558",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33558"
    },
    {
      "name": "CVE-2026-33846",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33846"
    },
    {
      "name": "CVE-2021-23337",
      "url": "https://www.cve.org/CVERecord?id=CVE-2021-23337"
    },
    {
      "name": "CVE-2026-5758",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5758"
    },
    {
      "name": "CVE-2026-34500",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34500"
    },
    {
      "name": "CVE-2026-54502",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54502"
    },
    {
      "name": "CVE-2026-22795",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22795"
    },
    {
      "name": "CVE-2026-29146",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-29146"
    },
    {
      "name": "CVE-2026-34043",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34043"
    },
    {
      "name": "CVE-2025-64718",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-64718"
    },
    {
      "name": "CVE-2026-9277",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9277"
    },
    {
      "name": "CVE-2026-27136",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27136"
    },
    {
      "name": "CVE-2025-62718",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-62718"
    },
    {
      "name": "CVE-2026-4800",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4800"
    },
    {
      "name": "CVE-2026-10536",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10536"
    },
    {
      "name": "CVE-2026-41844",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41844"
    },
    {
      "name": "CVE-2026-8932",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8932"
    },
    {
      "name": "CVE-2026-4424",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4424"
    },
    {
      "name": "CVE-2026-45292",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45292"
    },
    {
      "name": "CVE-2024-38820",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-38820"
    },
    {
      "name": "CVE-2026-40356",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40356"
    },
    {
      "name": "CVE-2026-15325",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15325"
    },
    {
      "name": "CVE-2026-14976",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14976"
    },
    {
      "name": "CVE-2026-5598",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5598"
    },
    {
      "name": "CVE-2026-42256",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42256"
    },
    {
      "name": "CVE-2026-42033",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42033"
    },
    {
      "name": "CVE-2025-59375",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59375"
    },
    {
      "name": "CVE-2026-54906",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54906"
    },
    {
      "name": "CVE-2026-34040",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34040"
    },
    {
      "name": "CVE-2026-42035",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42035"
    },
    {
      "name": "CVE-2026-41842",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41842"
    },
    {
      "name": "CVE-2026-44495",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44495"
    },
    {
      "name": "CVE-2026-41695",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41695"
    },
    {
      "name": "CVE-2026-14512",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14512"
    },
    {
      "name": "CVE-2026-11856",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11856"
    },
    {
      "name": "CVE-2026-44160",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44160"
    },
    {
      "name": "CVE-2026-42009",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42009"
    },
    {
      "name": "CVE-2026-33750",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33750"
    },
    {
      "name": "CVE-2026-5038",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5038"
    },
    {
      "name": "CVE-2026-34478",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34478"
    },
    {
      "name": "CVE-2026-2359",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2359"
    },
    {
      "name": "CVE-2026-42043",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42043"
    },
    {
      "name": "CVE-2025-11143",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-11143"
    },
    {
      "name": "CVE-2026-34480",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34480"
    },
    {
      "name": "CVE-2026-59869",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59869"
    },
    {
      "name": "CVE-2025-7783",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-7783"
    },
    {
      "name": "CVE-2025-12758",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-12758"
    },
    {
      "name": "CVE-2026-40175",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40175"
    },
    {
      "name": "CVE-2026-5079",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5079"
    },
    {
      "name": "CVE-2026-5795",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5795"
    },
    {
      "name": "CVE-2024-23953",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-23953"
    },
    {
      "name": "CVE-2025-68161",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68161"
    },
    {
      "name": "CVE-2026-44930",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44930"
    },
    {
      "name": "CVE-2026-14974",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14974"
    },
    {
      "name": "CVE-2024-29869",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-29869"
    },
    {
      "name": "CVE-2026-42010",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42010"
    },
    {
      "name": "CVE-2026-42506",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42506"
    },
    {
      "name": "CVE-2026-34479",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34479"
    },
    {
      "name": "CVE-2026-22796",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22796"
    },
    {
      "name": "CVE-2026-26960",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26960"
    },
    {
      "name": "CVE-2026-42040",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42040"
    },
    {
      "name": "CVE-2026-4867",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4867"
    },
    {
      "name": "CVE-2026-2303",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2303"
    },
    {
      "name": "CVE-2024-6763",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-6763"
    },
    {
      "name": "CVE-2026-27903",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27903"
    },
    {
      "name": "CVE-2026-14981",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14981"
    },
    {
      "name": "CVE-2026-39831",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39831"
    },
    {
      "name": "CVE-2026-39828",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39828"
    },
    {
      "name": "CVE-2026-8924",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8924"
    },
    {
      "name": "CVE-2024-45337",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-45337"
    },
    {
      "name": "CVE-2026-14529",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14529"
    },
    {
      "name": "CVE-2026-59875",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59875"
    },
    {
      "name": "CVE-2026-41843",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41843"
    },
    {
      "name": "CVE-2026-54896",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54896"
    },
    {
      "name": "CVE-2026-25680",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25680"
    },
    {
      "name": "CVE-2026-34487",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34487"
    },
    {
      "name": "CVE-2026-39835",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39835"
    },
    {
      "name": "CVE-2026-42578",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42578"
    },
    {
      "name": "CVE-2026-41850",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41850"
    },
    {
      "name": "CVE-2026-4519",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4519"
    },
    {
      "name": "CVE-2026-34197",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34197"
    },
    {
      "name": "CVE-2024-12905",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-12905"
    },
    {
      "name": "CVE-2024-52046",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-52046"
    },
    {
      "name": "CVE-2026-59873",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59873"
    },
    {
      "name": "CVE-2026-24842",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24842"
    },
    {
      "name": "CVE-2025-47935",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-47935"
    },
    {
      "name": "CVE-2026-40198",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40198"
    },
    {
      "name": "CVE-2026-4111",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4111"
    },
    {
      "name": "CVE-2024-38827",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-38827"
    },
    {
      "name": "CVE-2026-41694",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41694"
    },
    {
      "name": "CVE-2026-23950",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23950"
    },
    {
      "name": "CVE-2026-40046",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40046"
    },
    {
      "name": "CVE-2022-22968",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-22968"
    },
    {
      "name": "CVE-2026-16192",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16192"
    },
    {
      "name": "CVE-2026-2950",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2950"
    },
    {
      "name": "CVE-2026-54500",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54500"
    },
    {
      "name": "CVE-2026-3304",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3304"
    },
    {
      "name": "CVE-2026-40895",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40895"
    },
    {
      "name": "CVE-2018-10237",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-10237"
    },
    {
      "name": "CVE-2026-14515",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14515"
    },
    {
      "name": "CVE-2026-22016",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22016"
    },
    {
      "name": "CVE-2026-22021",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22021"
    },
    {
      "name": "CVE-2026-6100",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6100"
    },
    {
      "name": "CVE-2026-54904",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54904"
    },
    {
      "name": "CVE-2026-22007",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22007"
    },
    {
      "name": "CVE-2025-68160",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68160"
    },
    {
      "name": "CVE-2026-13149",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13149"
    },
    {
      "name": "CVE-2026-54897",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54897"
    },
    {
      "name": "CVE-2026-34268",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34268"
    },
    {
      "name": "CVE-2026-41852",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41852"
    },
    {
      "name": "CVE-2021-22569",
      "url": "https://www.cve.org/CVERecord?id=CVE-2021-22569"
    },
    {
      "name": "CVE-2026-3520",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3520"
    },
    {
      "name": "CVE-2026-29786",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-29786"
    },
    {
      "name": "CVE-2026-41006",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41006"
    },
    {
      "name": "CVE-2026-41711",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41711"
    },
    {
      "name": "CVE-2026-27830",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27830"
    },
    {
      "name": "CVE-2026-44487",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44487"
    },
    {
      "name": "CVE-2026-2482",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2482"
    },
    {
      "name": "CVE-2026-42038",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42038"
    },
    {
      "name": "CVE-2026-49844",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49844"
    },
    {
      "name": "CVE-2026-25854",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25854"
    },
    {
      "name": "CVE-2026-2332",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2332"
    },
    {
      "name": "CVE-2026-41851",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41851"
    },
    {
      "name": "CVE-2026-42039",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42039"
    },
    {
      "name": "CVE-2026-8149",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8149"
    },
    {
      "name": "CVE-2026-6009",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6009"
    },
    {
      "name": "CVE-2026-9358",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9358"
    },
    {
      "name": "CVE-2026-14446",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14446"
    },
    {
      "name": "CVE-2026-42502",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42502"
    },
    {
      "name": "CVE-2020-8908",
      "url": "https://www.cve.org/CVERecord?id=CVE-2020-8908"
    },
    {
      "name": "CVE-2026-42245",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42245"
    },
    {
      "name": "CVE-2026-8723",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8723"
    },
    {
      "name": "CVE-2026-40988",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40988"
    },
    {
      "name": "CVE-2026-41841",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41841"
    },
    {
      "name": "CVE-2026-25681",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25681"
    },
    {
      "name": "CVE-2025-69418",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69418"
    },
    {
      "name": "CVE-2026-54903",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54903"
    },
    {
      "name": "CVE-2026-39304",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39304"
    },
    {
      "name": "CVE-2026-49270",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49270"
    },
    {
      "name": "CVE-2025-15468",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15468"
    },
    {
      "name": "CVE-2026-25639",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25639"
    },
    {
      "name": "CVE-2026-15064",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15064"
    },
    {
      "name": "CVE-2026-42044",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42044"
    },
    {
      "name": "CVE-2026-54900",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54900"
    },
    {
      "name": "CVE-2018-16487",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-16487"
    },
    {
      "name": "CVE-2023-22899",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-22899"
    },
    {
      "name": "CVE-2026-42034",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42034"
    },
    {
      "name": "CVE-2026-8927",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8927"
    },
    {
      "name": "CVE-2026-41846",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41846"
    },
    {
      "name": "CVE-2025-5889",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-5889"
    },
    {
      "name": "CVE-2026-41035",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41035"
    },
    {
      "name": "CVE-2026-40199",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40199"
    },
    {
      "name": "CVE-2025-27789",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-27789"
    },
    {
      "name": "CVE-2026-46598",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46598"
    },
    {
      "name": "CVE-2026-44024",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44024"
    },
    {
      "name": "CVE-2026-42246",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42246"
    },
    {
      "name": "CVE-2025-66566",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-66566"
    },
    {
      "name": "CVE-2025-66168",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-66168"
    },
    {
      "name": "CVE-2026-41409",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41409"
    },
    {
      "name": "CVE-2025-11187",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-11187"
    },
    {
      "name": "CVE-2026-14980",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14980"
    },
    {
      "name": "CVE-2026-54898",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54898"
    },
    {
      "name": "CVE-2026-12143",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12143"
    },
    {
      "name": "CVE-2026-44431",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44431"
    },
    {
      "name": "CVE-2026-26996",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26996"
    },
    {
      "name": "CVE-2026-44486",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44486"
    },
    {
      "name": "CVE-2026-33227",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33227"
    },
    {
      "name": "CVE-2026-42264",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42264"
    },
    {
      "name": "CVE-2026-46597",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46597"
    },
    {
      "name": "CVE-2026-44161",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44161"
    },
    {
      "name": "CVE-2026-4786",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4786"
    },
    {
      "name": "CVE-2025-64756",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-64756"
    },
    {
      "name": "CVE-2026-34483",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34483"
    },
    {
      "name": "CVE-2026-44496",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44496"
    },
    {
      "name": "CVE-2026-0636",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0636"
    },
    {
      "name": "CVE-2026-44492",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44492"
    },
    {
      "name": "CVE-2025-48997",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-48997"
    },
    {
      "name": "CVE-2026-24880",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24880"
    },
    {
      "name": "CVE-2021-22570",
      "url": "https://www.cve.org/CVERecord?id=CVE-2021-22570"
    },
    {
      "name": "CVE-2026-9547",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9547"
    },
    {
      "name": "CVE-2026-41007",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41007"
    },
    {
      "name": "CVE-2026-42037",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42037"
    },
    {
      "name": "CVE-2026-2004",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2004"
    },
    {
      "name": "CVE-2026-42042",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42042"
    },
    {
      "name": "CVE-2025-21502",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-21502"
    },
    {
      "name": "CVE-2026-35554",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35554"
    },
    {
      "name": "CVE-2025-48387",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-48387"
    },
    {
      "name": "CVE-2026-12590",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12590"
    },
    {
      "name": "CVE-2026-27727",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27727"
    },
    {
      "name": "CVE-2026-34477",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34477"
    },
    {
      "name": "CVE-2026-54902",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54902"
    },
    {
      "name": "CVE-2026-44490",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44490"
    },
    {
      "name": "CVE-2026-54592",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54592"
    },
    {
      "name": "CVE-2023-5752",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-5752"
    },
    {
      "name": "CVE-2026-39827",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39827"
    },
    {
      "name": "CVE-2025-12183",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-12183"
    },
    {
      "name": "CVE-2025-7338",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-7338"
    },
    {
      "name": "CVE-2026-15280",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15280"
    },
    {
      "name": "CVE-2026-41848",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41848"
    },
    {
      "name": "CVE-2025-14813",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-14813"
    },
    {
      "name": "CVE-2026-31802",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-31802"
    },
    {
      "name": "CVE-2025-13465",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-13465"
    },
    {
      "name": "CVE-2026-13311",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13311"
    },
    {
      "name": "CVE-2026-41907",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41907"
    },
    {
      "name": "CVE-2026-44488",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44488"
    },
    {
      "name": "CVE-2025-59343",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59343"
    },
    {
      "name": "CVE-2026-34481",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34481"
    },
    {
      "name": "CVE-2026-27904",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27904"
    },
    {
      "name": "CVE-2026-8286",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8286"
    },
    {
      "name": "CVE-2026-42257",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42257"
    },
    {
      "name": "CVE-2026-42338",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42338"
    }
  ],
  "initial_release_date": "2026-07-31T00:00:00",
  "last_revision_date": "2026-07-31T00:00:00",
  "links": [],
  "reference": "CERTFR-2026-AVI-0958",
  "revisions": [
    {
      "description": "Version initiale",
      "revision_date": "2026-07-31T00:00:00.000000"
    }
  ],
  "risks": [
    {
      "description": "D\u00e9ni de service \u00e0 distance"
    },
    {
      "description": "Injection de code indirecte \u00e0 distance (XSS)"
    },
    {
      "description": "Injection de requ\u00eates ill\u00e9gitimes par rebond (CSRF)"
    },
    {
      "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
    },
    {
      "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
    },
    {
      "description": "Injection SQL (SQLi)"
    },
    {
      "description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
    },
    {
      "description": "Falsification de requ\u00eates c\u00f4t\u00e9 serveur (SSRF)"
    },
    {
      "description": "Contournement de la politique de s\u00e9curit\u00e9"
    },
    {
      "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
    },
    {
      "description": "\u00c9l\u00e9vation de privil\u00e8ges"
    }
  ],
  "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits IBM. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance, une \u00e9l\u00e9vation de privil\u00e8ges et un d\u00e9ni de service \u00e0 distance.",
  "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits IBM",
  "vendor_advisories": [
    {
      "published_at": "2026-07-27",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7281450",
      "url": "https://www.ibm.com/support/pages/node/7281450"
    },
    {
      "published_at": "2026-07-28",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7281625",
      "url": "https://www.ibm.com/support/pages/node/7281625"
    },
    {
      "published_at": "2026-07-30",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7281949",
      "url": "https://www.ibm.com/support/pages/node/7281949"
    },
    {
      "published_at": "2026-07-27",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7277692",
      "url": "https://www.ibm.com/support/pages/node/7277692"
    },
    {
      "published_at": "2026-07-28",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7281628",
      "url": "https://www.ibm.com/support/pages/node/7281628"
    },
    {
      "published_at": "2026-07-24",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7281135",
      "url": "https://www.ibm.com/support/pages/node/7281135"
    },
    {
      "published_at": "2026-07-27",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7281375",
      "url": "https://www.ibm.com/support/pages/node/7281375"
    },
    {
      "published_at": "2026-07-29",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7281743",
      "url": "https://www.ibm.com/support/pages/node/7281743"
    },
    {
      "published_at": "2026-07-27",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7281373",
      "url": "https://www.ibm.com/support/pages/node/7281373"
    },
    {
      "published_at": "2026-07-27",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7281388",
      "url": "https://www.ibm.com/support/pages/node/7281388"
    },
    {
      "published_at": "2026-07-28",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7281721",
      "url": "https://www.ibm.com/support/pages/node/7281721"
    },
    {
      "published_at": "2026-07-27",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7281369",
      "url": "https://www.ibm.com/support/pages/node/7281369"
    },
    {
      "published_at": "2026-07-28",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7281648",
      "url": "https://www.ibm.com/support/pages/node/7281648"
    },
    {
      "published_at": "2026-07-27",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7281374",
      "url": "https://www.ibm.com/support/pages/node/7281374"
    },
    {
      "published_at": "2026-07-24",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7281136",
      "url": "https://www.ibm.com/support/pages/node/7281136"
    },
    {
      "published_at": "2026-07-28",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7281641",
      "url": "https://www.ibm.com/support/pages/node/7281641"
    },
    {
      "published_at": "2026-07-28",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7281631",
      "url": "https://www.ibm.com/support/pages/node/7281631"
    },
    {
      "published_at": "2026-07-27",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7281371",
      "url": "https://www.ibm.com/support/pages/node/7281371"
    },
    {
      "published_at": "2026-07-28",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7281633",
      "url": "https://www.ibm.com/support/pages/node/7281633"
    },
    {
      "published_at": "2026-07-27",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7281438",
      "url": "https://www.ibm.com/support/pages/node/7281438"
    },
    {
      "published_at": "2026-07-27",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7281370",
      "url": "https://www.ibm.com/support/pages/node/7281370"
    },
    {
      "published_at": "2026-07-27",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7281565",
      "url": "https://www.ibm.com/support/pages/node/7281565"
    },
    {
      "published_at": "2026-07-27",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7281368",
      "url": "https://www.ibm.com/support/pages/node/7281368"
    },
    {
      "published_at": "2026-07-27",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7281350",
      "url": "https://www.ibm.com/support/pages/node/7281350"
    },
    {
      "published_at": "2026-07-28",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7281651",
      "url": "https://www.ibm.com/support/pages/node/7281651"
    },
    {
      "published_at": "2026-07-30",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7281950",
      "url": "https://www.ibm.com/support/pages/node/7281950"
    },
    {
      "published_at": "2026-07-27",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7281567",
      "url": "https://www.ibm.com/support/pages/node/7281567"
    },
    {
      "published_at": "2026-07-23",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7280950",
      "url": "https://www.ibm.com/support/pages/node/7280950"
    },
    {
      "published_at": "2026-07-27",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7281441",
      "url": "https://www.ibm.com/support/pages/node/7281441"
    },
    {
      "published_at": "2026-07-28",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7281649",
      "url": "https://www.ibm.com/support/pages/node/7281649"
    }
  ]
}

CERTFR-2026-AVI-0901
Vulnerability from certfr_avis

De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

Solutions

Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

Impacted products
Vendor Product Description
IBM WebSphere Application Server WebSphere Application Server Liberty versions antérieures à 26.0.0.8
IBM Sterling Connect:Direct Sterling Connect:Direct FTP+ versions antérieures à 1.3.0.5
IBM QRadar QRadar User Behavior Analytics versions antérieures à 6.0.0
IBM Db2 Db2 Genius Hub & Agentics versions antérieures à 1.1.3
IBM QRadar QRadar Data Synchronization App versions antérieures à 4.0.0
IBM QRadar Security QRadar Log Management AQL Plugin versions antérieures à 1.1.7
IBM Db2 Db2 versions 12.1.x antérieures à 12.1.4
IBM Sterling Connect:Direct Sterling Connect:Direct versions 6.4.x antérieures à 6.4.0.5.iFix020 pour Unix
IBM Db2 Db2 versions 11.5.x antérieures à 11.5.9
IBM Sterling Connect:Direct Sterling Connect:Direct Web Services versions 6.3.x antérieures à 6.3.0.20
IBM WebSphere Application Server WebSphere Application Server versions 8.5.x antérieures à 8.5.5.31
IBM Sterling Connect:Direct Sterling Secure Proxy versions antérieures à 6.2.1.2 iFix02
IBM Sterling Connect:Direct Sterling Connect:Direct versions 6.3.x antérieures à 6.3.0.7.iFix015 pour Unix
IBM WebSphere Application Server WebSphere Application Server versions 9.0.x antérieures à 9.0.5.29
IBM Sterling Connect:Direct Sterling Connect:Direct Web Services versions 6.4.x antérieures à 6.4.0.9
References
Bulletin de sécurité IBM 7279972 2026-07-14 vendor-advisory
Bulletin de sécurité IBM 7280010 2026-07-14 vendor-advisory
Bulletin de sécurité IBM 7279458 2026-07-10 vendor-advisory
Bulletin de sécurité IBM 7280089 2026-07-15 vendor-advisory
Bulletin de sécurité IBM 7280183 2026-07-15 vendor-advisory
Bulletin de sécurité IBM 7280131 2026-07-15 vendor-advisory
Bulletin de sécurité IBM 7279924 2026-07-13 vendor-advisory
Bulletin de sécurité IBM 7280105 2026-07-15 vendor-advisory
Bulletin de sécurité IBM 7279466 2026-08-27 vendor-advisory
Bulletin de sécurité IBM 7280009 2026-07-14 vendor-advisory
Bulletin de sécurité IBM 7279973 2026-07-14 vendor-advisory
Bulletin de sécurité IBM 7279901 2026-07-13 vendor-advisory

Show details on source website


{
  "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
  "affected_systems": [
    {
      "description": "WebSphere Application Server Liberty versions ant\u00e9rieures \u00e0 26.0.0.8",
      "product": {
        "name": "WebSphere Application Server",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Sterling Connect:Direct FTP+ versions ant\u00e9rieures \u00e0 1.3.0.5",
      "product": {
        "name": "Sterling Connect:Direct",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "QRadar User Behavior Analytics versions ant\u00e9rieures \u00e0 6.0.0",
      "product": {
        "name": "QRadar",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Db2 Genius Hub \u0026 Agentics versions ant\u00e9rieures \u00e0 1.1.3",
      "product": {
        "name": "Db2",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "QRadar Data Synchronization App versions ant\u00e9rieures \u00e0 4.0.0",
      "product": {
        "name": "QRadar",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Security QRadar Log Management AQL Plugin versions ant\u00e9rieures \u00e0 1.1.7",
      "product": {
        "name": "QRadar",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Db2 versions 12.1.x ant\u00e9rieures \u00e0 12.1.4",
      "product": {
        "name": "Db2",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Sterling Connect:Direct versions 6.4.x ant\u00e9rieures \u00e0 6.4.0.5.iFix020 pour Unix",
      "product": {
        "name": "Sterling Connect:Direct",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Db2 versions 11.5.x ant\u00e9rieures \u00e0 11.5.9",
      "product": {
        "name": "Db2",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Sterling Connect:Direct Web Services versions 6.3.x ant\u00e9rieures \u00e0 6.3.0.20",
      "product": {
        "name": "Sterling Connect:Direct",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "WebSphere Application Server versions 8.5.x ant\u00e9rieures \u00e0 8.5.5.31",
      "product": {
        "name": "WebSphere Application Server",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Sterling Secure Proxy versions ant\u00e9rieures \u00e0 6.2.1.2 iFix02",
      "product": {
        "name": "Sterling Connect:Direct",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Sterling Connect:Direct versions 6.3.x ant\u00e9rieures \u00e0 6.3.0.7.iFix015 pour Unix",
      "product": {
        "name": "Sterling Connect:Direct",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "WebSphere Application Server versions 9.0.x ant\u00e9rieures \u00e0 9.0.5.29",
      "product": {
        "name": "WebSphere Application Server",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Sterling Connect:Direct Web Services versions 6.4.x ant\u00e9rieures \u00e0 6.4.0.9",
      "product": {
        "name": "Sterling Connect:Direct",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    }
  ],
  "affected_systems_content": "",
  "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
  "cves": [
    {
      "name": "CVE-2026-27980",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27980"
    },
    {
      "name": "CVE-2022-31129",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-31129"
    },
    {
      "name": "CVE-2026-44574",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44574"
    },
    {
      "name": "CVE-2026-44578",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44578"
    },
    {
      "name": "CVE-2026-3449",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3449"
    },
    {
      "name": "CVE-2026-27205",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27205"
    },
    {
      "name": "CVE-2026-31958",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-31958"
    },
    {
      "name": "CVE-2026-23479",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23479"
    },
    {
      "name": "CVE-2026-45109",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45109"
    },
    {
      "name": "CVE-2024-37891",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-37891"
    },
    {
      "name": "CVE-2026-50645",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50645"
    },
    {
      "name": "CVE-2026-39830",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39830"
    },
    {
      "name": "CVE-2026-42041",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42041"
    },
    {
      "name": "CVE-2025-67726",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-67726"
    },
    {
      "name": "CVE-2026-44573",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44573"
    },
    {
      "name": "CVE-2026-44580",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44580"
    },
    {
      "name": "CVE-2026-42508",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42508"
    },
    {
      "name": "CVE-2025-14505",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-14505"
    },
    {
      "name": "CVE-2026-44579",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44579"
    },
    {
      "name": "CVE-2026-42211",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42211"
    },
    {
      "name": "CVE-2023-37920",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-37920"
    },
    {
      "name": "CVE-2026-9171",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9171"
    },
    {
      "name": "CVE-2026-39833",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39833"
    },
    {
      "name": "CVE-2026-41239",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41239"
    },
    {
      "name": "CVE-2026-41305",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41305"
    },
    {
      "name": "CVE-2026-33814",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33814"
    },
    {
      "name": "CVE-2026-44575",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44575"
    },
    {
      "name": "CVE-2026-2391",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2391"
    },
    {
      "name": "CVE-2026-53663",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53663"
    },
    {
      "name": "CVE-2026-22013",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22013"
    },
    {
      "name": "CVE-2026-22018",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22018"
    },
    {
      "name": "CVE-2026-39832",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39832"
    },
    {
      "name": "CVE-2026-39829",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39829"
    },
    {
      "name": "CVE-2026-41988",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41988"
    },
    {
      "name": "CVE-2026-23745",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23745"
    },
    {
      "name": "CVE-2024-29415",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-29415"
    },
    {
      "name": "CVE-2025-59471",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59471"
    },
    {
      "name": "CVE-2026-7246",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7246"
    },
    {
      "name": "CVE-2026-35536",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35536"
    },
    {
      "name": "CVE-2026-39834",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39834"
    },
    {
      "name": "CVE-2025-15284",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15284"
    },
    {
      "name": "CVE-2026-22029",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22029"
    },
    {
      "name": "CVE-2026-46595",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46595"
    },
    {
      "name": "CVE-2026-34282",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34282"
    },
    {
      "name": "CVE-2026-42036",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42036"
    },
    {
      "name": "CVE-2026-54285",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54285"
    },
    {
      "name": "CVE-2026-24051",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24051"
    },
    {
      "name": "CVE-2025-59472",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59472"
    },
    {
      "name": "CVE-2026-44572",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44572"
    },
    {
      "name": "CVE-2026-39821",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39821"
    },
    {
      "name": "CVE-2021-23337",
      "url": "https://www.cve.org/CVERecord?id=CVE-2021-23337"
    },
    {
      "name": "CVE-2026-34043",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34043"
    },
    {
      "name": "CVE-2026-45409",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45409"
    },
    {
      "name": "CVE-2026-27136",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27136"
    },
    {
      "name": "CVE-2025-62718",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-62718"
    },
    {
      "name": "CVE-2026-25645",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25645"
    },
    {
      "name": "CVE-2026-21860",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21860"
    },
    {
      "name": "CVE-2026-4800",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4800"
    },
    {
      "name": "CVE-2026-44249",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44249"
    },
    {
      "name": "CVE-2026-39883",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39883"
    },
    {
      "name": "CVE-2026-0540",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0540"
    },
    {
      "name": "CVE-2026-45149",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45149"
    },
    {
      "name": "CVE-2026-45249",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45249"
    },
    {
      "name": "CVE-2026-23865",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23865"
    },
    {
      "name": "CVE-2020-7760",
      "url": "https://www.cve.org/CVERecord?id=CVE-2020-7760"
    },
    {
      "name": "CVE-2026-33671",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33671"
    },
    {
      "name": "CVE-2026-33532",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33532"
    },
    {
      "name": "CVE-2025-68470",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68470"
    },
    {
      "name": "CVE-2026-42033",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42033"
    },
    {
      "name": "CVE-2026-42035",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42035"
    },
    {
      "name": "CVE-2026-30922",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30922"
    },
    {
      "name": "CVE-2025-50181",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-50181"
    },
    {
      "name": "CVE-2026-10842",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10842"
    },
    {
      "name": "CVE-2026-25589",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25589"
    },
    {
      "name": "CVE-2026-33750",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33750"
    },
    {
      "name": "CVE-2026-2359",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2359"
    },
    {
      "name": "CVE-2026-42043",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42043"
    },
    {
      "name": "CVE-2025-11143",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-11143"
    },
    {
      "name": "CVE-2026-6918",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6918"
    },
    {
      "name": "CVE-2026-40175",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40175"
    },
    {
      "name": "CVE-2026-5795",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5795"
    },
    {
      "name": "CVE-2025-6493",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-6493"
    },
    {
      "name": "CVE-2026-41240",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41240"
    },
    {
      "name": "CVE-2026-42506",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42506"
    },
    {
      "name": "CVE-2026-34479",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34479"
    },
    {
      "name": "CVE-2024-52804",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-52804"
    },
    {
      "name": "CVE-2026-26960",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26960"
    },
    {
      "name": "CVE-2022-21704",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-21704"
    },
    {
      "name": "CVE-2026-42040",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42040"
    },
    {
      "name": "CVE-2026-4867",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4867"
    },
    {
      "name": "CVE-2025-23165",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-23165"
    },
    {
      "name": "CVE-2023-45803",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-45803"
    },
    {
      "name": "CVE-2026-27199",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27199"
    },
    {
      "name": "CVE-2026-2492",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2492"
    },
    {
      "name": "CVE-2026-27903",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27903"
    },
    {
      "name": "CVE-2026-39831",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39831"
    },
    {
      "name": "CVE-2026-39828",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39828"
    },
    {
      "name": "CVE-2025-66471",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-66471"
    },
    {
      "name": "CVE-2026-21441",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21441"
    },
    {
      "name": "CVE-2024-45337",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-45337"
    },
    {
      "name": "CVE-2026-44581",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44581"
    },
    {
      "name": "CVE-2026-40181",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40181"
    },
    {
      "name": "CVE-2026-25680",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25680"
    },
    {
      "name": "CVE-2026-39835",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39835"
    },
    {
      "name": "CVE-2026-29057",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-29057"
    },
    {
      "name": "CVE-2026-23631",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23631"
    },
    {
      "name": "CVE-2024-35195",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-35195"
    },
    {
      "name": "CVE-2026-4539",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4539"
    },
    {
      "name": "CVE-2022-24785",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-24785"
    },
    {
      "name": "CVE-2026-44577",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44577"
    },
    {
      "name": "CVE-2026-24842",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24842"
    },
    {
      "name": "CVE-2025-66221",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-66221"
    },
    {
      "name": "CVE-2026-23950",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23950"
    },
    {
      "name": "CVE-2026-2950",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2950"
    },
    {
      "name": "CVE-2026-3304",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3304"
    },
    {
      "name": "CVE-2026-40895",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40895"
    },
    {
      "name": "CVE-2026-22016",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22016"
    },
    {
      "name": "CVE-2026-22021",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22021"
    },
    {
      "name": "CVE-2026-25243",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25243"
    },
    {
      "name": "CVE-2023-43804",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-43804"
    },
    {
      "name": "CVE-2026-22007",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22007"
    },
    {
      "name": "CVE-2026-54270",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54270"
    },
    {
      "name": "CVE-2025-69873",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69873"
    },
    {
      "name": "CVE-2024-6485",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-6485"
    },
    {
      "name": "CVE-2026-34268",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34268"
    },
    {
      "name": "CVE-2025-68458",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68458"
    },
    {
      "name": "CVE-2026-3520",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3520"
    },
    {
      "name": "CVE-2026-44582",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44582"
    },
    {
      "name": "CVE-2026-29786",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-29786"
    },
    {
      "name": "CVE-2026-42038",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42038"
    },
    {
      "name": "CVE-2026-2332",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2332"
    },
    {
      "name": "CVE-2026-11708",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11708"
    },
    {
      "name": "CVE-2026-42039",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42039"
    },
    {
      "name": "CVE-2025-15599",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15599"
    },
    {
      "name": "CVE-2026-14501",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14501"
    },
    {
      "name": "CVE-2024-47081",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-47081"
    },
    {
      "name": "CVE-2026-42502",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42502"
    },
    {
      "name": "CVE-2026-33672",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33672"
    },
    {
      "name": "CVE-2026-27459",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27459"
    },
    {
      "name": "CVE-2020-28500",
      "url": "https://www.cve.org/CVERecord?id=CVE-2020-28500"
    },
    {
      "name": "CVE-2026-25681",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25681"
    },
    {
      "name": "CVE-2026-39304",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39304"
    },
    {
      "name": "CVE-2026-25639",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25639"
    },
    {
      "name": "CVE-2026-42044",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42044"
    },
    {
      "name": "CVE-2020-8203",
      "url": "https://www.cve.org/CVERecord?id=CVE-2020-8203"
    },
    {
      "name": "CVE-2026-27448",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27448"
    },
    {
      "name": "CVE-2022-40896",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-40896"
    },
    {
      "name": "CVE-2026-11595",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11595"
    },
    {
      "name": "CVE-2026-42034",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42034"
    },
    {
      "name": "CVE-2025-59437",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59437"
    },
    {
      "name": "CVE-2026-9322",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9322"
    },
    {
      "name": "CVE-2026-8408",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8408"
    },
    {
      "name": "CVE-2026-44576",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44576"
    },
    {
      "name": "CVE-2026-23490",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23490"
    },
    {
      "name": "CVE-2025-71176",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71176"
    },
    {
      "name": "CVE-2025-68157",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68157"
    },
    {
      "name": "CVE-2026-46598",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46598"
    },
    {
      "name": "CVE-2026-6322",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6322"
    },
    {
      "name": "CVE-2026-11712",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11712"
    },
    {
      "name": "CVE-2026-42342",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42342"
    },
    {
      "name": "CVE-2026-12143",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12143"
    },
    {
      "name": "CVE-2026-44431",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44431"
    },
    {
      "name": "CVE-2024-3651",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-3651"
    },
    {
      "name": "CVE-2026-26996",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26996"
    },
    {
      "name": "CVE-2026-33227",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33227"
    },
    {
      "name": "CVE-2026-42264",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42264"
    },
    {
      "name": "CVE-2026-46597",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46597"
    },
    {
      "name": "CVE-2025-67724",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-67724"
    },
    {
      "name": "CVE-2026-39865",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39865"
    },
    {
      "name": "CVE-2026-41238",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41238"
    },
    {
      "name": "CVE-2026-54269",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54269"
    },
    {
      "name": "CVE-2026-28684",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28684"
    },
    {
      "name": "CVE-2025-59436",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59436"
    },
    {
      "name": "CVE-2026-42037",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42037"
    },
    {
      "name": "CVE-2026-42042",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42042"
    },
    {
      "name": "CVE-2023-42282",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-42282"
    },
    {
      "name": "CVE-2023-32681",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-32681"
    },
    {
      "name": "CVE-2026-6321",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6321"
    },
    {
      "name": "CVE-2024-39689",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-39689"
    },
    {
      "name": "CVE-2026-39827",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39827"
    },
    {
      "name": "CVE-2025-67725",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-67725"
    },
    {
      "name": "CVE-2026-29063",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-29063"
    },
    {
      "name": "CVE-2026-22008",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22008"
    },
    {
      "name": "CVE-2026-31802",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-31802"
    },
    {
      "name": "CVE-2025-13465",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-13465"
    },
    {
      "name": "CVE-2026-41907",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41907"
    },
    {
      "name": "CVE-2026-10535",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10535"
    },
    {
      "name": "CVE-2026-27904",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27904"
    },
    {
      "name": "CVE-2026-34077",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34077"
    },
    {
      "name": "CVE-2026-2739",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2739"
    },
    {
      "name": "CVE-2025-47287",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-47287"
    },
    {
      "name": "CVE-2025-66418",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-66418"
    }
  ],
  "initial_release_date": "2026-07-17T00:00:00",
  "last_revision_date": "2026-07-17T00:00:00",
  "links": [],
  "reference": "CERTFR-2026-AVI-0901",
  "revisions": [
    {
      "description": "Version initiale",
      "revision_date": "2026-07-17T00:00:00.000000"
    }
  ],
  "risks": [
    {
      "description": "D\u00e9ni de service \u00e0 distance"
    },
    {
      "description": "Injection de code indirecte \u00e0 distance (XSS)"
    },
    {
      "description": "Injection de requ\u00eates ill\u00e9gitimes par rebond (CSRF)"
    },
    {
      "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
    },
    {
      "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
    },
    {
      "description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
    },
    {
      "description": "Falsification de requ\u00eates c\u00f4t\u00e9 serveur (SSRF)"
    },
    {
      "description": "Contournement de la politique de s\u00e9curit\u00e9"
    },
    {
      "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
    },
    {
      "description": "\u00c9l\u00e9vation de privil\u00e8ges"
    }
  ],
  "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits IBM. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance, une \u00e9l\u00e9vation de privil\u00e8ges et un d\u00e9ni de service \u00e0 distance.",
  "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits IBM",
  "vendor_advisories": [
    {
      "published_at": "2026-07-14",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7279972",
      "url": "https://www.ibm.com/support/pages/node/7279972"
    },
    {
      "published_at": "2026-07-14",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7280010",
      "url": "https://www.ibm.com/support/pages/node/7280010"
    },
    {
      "published_at": "2026-07-10",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7279458",
      "url": "https://www.ibm.com/support/pages/node/7279458"
    },
    {
      "published_at": "2026-07-15",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7280089",
      "url": "https://www.ibm.com/support/pages/node/7280089"
    },
    {
      "published_at": "2026-07-15",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7280183",
      "url": "https://www.ibm.com/support/pages/node/7280183"
    },
    {
      "published_at": "2026-07-15",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7280131",
      "url": "https://www.ibm.com/support/pages/node/7280131"
    },
    {
      "published_at": "2026-07-13",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7279924",
      "url": "https://www.ibm.com/support/pages/node/7279924"
    },
    {
      "published_at": "2026-07-15",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7280105",
      "url": "https://www.ibm.com/support/pages/node/7280105"
    },
    {
      "published_at": "2026-08-27",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7279466",
      "url": "https://www.ibm.com/support/pages/node/7279466"
    },
    {
      "published_at": "2026-07-14",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7280009",
      "url": "https://www.ibm.com/support/pages/node/7280009"
    },
    {
      "published_at": "2026-07-14",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7279973",
      "url": "https://www.ibm.com/support/pages/node/7279973"
    },
    {
      "published_at": "2026-07-13",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7279901",
      "url": "https://www.ibm.com/support/pages/node/7279901"
    }
  ]
}

CERTFR-2026-AVI-0834
Vulnerability from certfr_avis

De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

Solutions

Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

Impacted products
Vendor Product Description
IBM WebSphere WebSphere Application Server versions 9.x antérieures à 9.0.5.29
IBM Db2 Db2 Genius Hub versions antérieures à 1.1.3
IBM Db2 Db2 Big SQL on IBM Software Hub versions antérieures à 5.4
IBM WebSphere WebSphere Remote Server versions 9.x antérieures à 9.0.5.29
IBM N/A SOAR QRadar Plugin App versions antérieures à 5.6.5
IBM WebSphere WebSphere Remote Server versions 8.5.x antérieures à 8.5.5.31
IBM WebSphere WebSphere Application Server versions 8.x antérieures à 8.5.5.31
IBM WebSphere WebSphere Application Server Liberty versions antérieures à 26.0.0.8
References
Bulletin de sécurité IBM 7278360 2026-06-29 vendor-advisory
Bulletin de sécurité IBM 7279004 2026-07-02 vendor-advisory
Bulletin de sécurité IBM 7278998 2026-07-02 vendor-advisory
Bulletin de sécurité IBM 7278996 2026-07-02 vendor-advisory
Bulletin de sécurité IBM 7278993 2026-07-02 vendor-advisory
Bulletin de sécurité IBM 7279001 2026-07-02 vendor-advisory
Bulletin de sécurité IBM 7278935 2026-07-02 vendor-advisory
Bulletin de sécurité IBM 7278590 2026-06-30 vendor-advisory
Bulletin de sécurité IBM 7278148 2026-06-26 vendor-advisory
Bulletin de sécurité IBM 7279002 2026-07-02 vendor-advisory
Bulletin de sécurité IBM 7278995 2026-07-02 vendor-advisory
Bulletin de sécurité IBM 7278997 2026-07-02 vendor-advisory
Bulletin de sécurité IBM 7278990 2026-07-02 vendor-advisory
Bulletin de sécurité IBM 7278358 2026-06-29 vendor-advisory
Bulletin de sécurité IBM 7278989 2026-07-02 vendor-advisory
Bulletin de sécurité IBM 7278576 2026-06-30 vendor-advisory
Bulletin de sécurité IBM 7278572 2026-06-30 vendor-advisory
Bulletin de sécurité IBM 7278580 2026-06-30 vendor-advisory
Bulletin de sécurité IBM 7278398 2026-06-29 vendor-advisory
Bulletin de sécurité IBM 7278359 2026-06-29 vendor-advisory
Bulletin de sécurité IBM 7279003 2026-07-02 vendor-advisory
Bulletin de sécurité IBM 7278103 2026-06-26 vendor-advisory
Bulletin de sécurité IBM 7278593 2026-06-30 vendor-advisory
Bulletin de sécurité IBM 7278399 2026-06-29 vendor-advisory

Show details on source website


{
  "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
  "affected_systems": [
    {
      "description": "WebSphere Application Server versions 9.x ant\u00e9rieures \u00e0 9.0.5.29",
      "product": {
        "name": "WebSphere",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Db2 Genius Hub versions ant\u00e9rieures \u00e0 1.1.3",
      "product": {
        "name": "Db2",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Db2 Big SQL on IBM Software Hub versions ant\u00e9rieures \u00e0 5.4",
      "product": {
        "name": "Db2",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "WebSphere Remote Server versions 9.x ant\u00e9rieures \u00e0 9.0.5.29",
      "product": {
        "name": "WebSphere",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "SOAR QRadar Plugin App versions ant\u00e9rieures \u00e0 5.6.5",
      "product": {
        "name": "N/A",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "WebSphere Remote Server versions 8.5.x ant\u00e9rieures \u00e0 8.5.5.31",
      "product": {
        "name": "WebSphere",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "WebSphere Application Server versions 8.x ant\u00e9rieures \u00e0 8.5.5.31",
      "product": {
        "name": "WebSphere",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "WebSphere Application Server Liberty versions ant\u00e9rieures \u00e0 26.0.0.8",
      "product": {
        "name": "WebSphere",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    }
  ],
  "affected_systems_content": "",
  "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
  "cves": [
    {
      "name": "CVE-2026-50645",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50645"
    },
    {
      "name": "CVE-2026-11383",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11383"
    },
    {
      "name": "CVE-2026-42041",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42041"
    },
    {
      "name": "CVE-2026-39892",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39892"
    },
    {
      "name": "CVE-2024-7531",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-7531"
    },
    {
      "name": "CVE-2021-3572",
      "url": "https://www.cve.org/CVERecord?id=CVE-2021-3572"
    },
    {
      "name": "CVE-2026-44432",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44432"
    },
    {
      "name": "CVE-2025-14688",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-14688"
    },
    {
      "name": "CVE-2026-9171",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9171"
    },
    {
      "name": "CVE-2024-12086",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-12086"
    },
    {
      "name": "CVE-2026-1577",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1577"
    },
    {
      "name": "CVE-2025-6069",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-6069"
    },
    {
      "name": "CVE-2026-2391",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2391"
    },
    {
      "name": "CVE-2026-9072",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9072"
    },
    {
      "name": "CVE-2026-24737",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24737"
    },
    {
      "name": "CVE-2026-8858",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8858"
    },
    {
      "name": "CVE-2026-7246",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7246"
    },
    {
      "name": "CVE-2025-15284",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15284"
    },
    {
      "name": "CVE-2026-22029",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22029"
    },
    {
      "name": "CVE-2026-11541",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11541"
    },
    {
      "name": "CVE-2025-1371",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-1371"
    },
    {
      "name": "CVE-2026-11707",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11707"
    },
    {
      "name": "CVE-2026-11546",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11546"
    },
    {
      "name": "CVE-2026-42036",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42036"
    },
    {
      "name": "CVE-2021-23337",
      "url": "https://www.cve.org/CVERecord?id=CVE-2021-23337"
    },
    {
      "name": "CVE-2026-11594",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11594"
    },
    {
      "name": "CVE-2025-8291",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-8291"
    },
    {
      "name": "CVE-2025-64718",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-64718"
    },
    {
      "name": "CVE-2026-24043",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24043"
    },
    {
      "name": "CVE-2025-13755",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-13755"
    },
    {
      "name": "CVE-2025-62718",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-62718"
    },
    {
      "name": "CVE-2026-4800",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4800"
    },
    {
      "name": "CVE-2026-6051",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6051"
    },
    {
      "name": "CVE-2025-50182",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-50182"
    },
    {
      "name": "CVE-2026-33671",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33671"
    },
    {
      "name": "CVE-2026-33532",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33532"
    },
    {
      "name": "CVE-2025-68470",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68470"
    },
    {
      "name": "CVE-2026-42033",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42033"
    },
    {
      "name": "CVE-2026-42035",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42035"
    },
    {
      "name": "CVE-2026-11536",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11536"
    },
    {
      "name": "CVE-2025-50181",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-50181"
    },
    {
      "name": "CVE-2025-1795",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-1795"
    },
    {
      "name": "CVE-2026-33750",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33750"
    },
    {
      "name": "CVE-2026-42043",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42043"
    },
    {
      "name": "CVE-2026-8646",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8646"
    },
    {
      "name": "CVE-2026-33228",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33228"
    },
    {
      "name": "CVE-2026-9320",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9320"
    },
    {
      "name": "CVE-2026-6053",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6053"
    },
    {
      "name": "CVE-2025-68161",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68161"
    },
    {
      "name": "CVE-2024-29869",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-29869"
    },
    {
      "name": "CVE-2026-42040",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42040"
    },
    {
      "name": "CVE-2026-4923",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4923"
    },
    {
      "name": "CVE-2026-6052",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6052"
    },
    {
      "name": "CVE-2025-1377",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-1377"
    },
    {
      "name": "CVE-2026-27903",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27903"
    },
    {
      "name": "CVE-2024-25260",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-25260"
    },
    {
      "name": "CVE-2026-24133",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24133"
    },
    {
      "name": "CVE-2026-10845",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10845"
    },
    {
      "name": "CVE-2026-2327",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2327"
    },
    {
      "name": "CVE-2026-2950",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2950"
    },
    {
      "name": "CVE-2026-3676",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3676"
    },
    {
      "name": "CVE-2026-1352",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1352"
    },
    {
      "name": "CVE-2025-1376",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-1376"
    },
    {
      "name": "CVE-2025-69873",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69873"
    },
    {
      "name": "CVE-2025-67735",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-67735"
    },
    {
      "name": "CVE-2025-36122",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36122"
    },
    {
      "name": "CVE-2026-25940",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25940"
    },
    {
      "name": "CVE-2026-24040",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24040"
    },
    {
      "name": "CVE-2026-42038",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42038"
    },
    {
      "name": "CVE-2026-11708",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11708"
    },
    {
      "name": "CVE-2026-42039",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42039"
    },
    {
      "name": "CVE-2026-25755",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25755"
    },
    {
      "name": "CVE-2026-33672",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33672"
    },
    {
      "name": "CVE-2025-58181",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-58181"
    },
    {
      "name": "CVE-2025-47914",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-47914"
    },
    {
      "name": "CVE-2025-4516",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-4516"
    },
    {
      "name": "CVE-2026-25639",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25639"
    },
    {
      "name": "CVE-2026-42044",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42044"
    },
    {
      "name": "CVE-2026-11595",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11595"
    },
    {
      "name": "CVE-2026-11714",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11714"
    },
    {
      "name": "CVE-2026-25535",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25535"
    },
    {
      "name": "CVE-2026-42034",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42034"
    },
    {
      "name": "CVE-2026-9322",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9322"
    },
    {
      "name": "CVE-2026-31938",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-31938"
    },
    {
      "name": "CVE-2025-48924",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-48924"
    },
    {
      "name": "CVE-2026-6938",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6938"
    },
    {
      "name": "CVE-2026-11712",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11712"
    },
    {
      "name": "CVE-2026-44431",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44431"
    },
    {
      "name": "CVE-2026-42264",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42264"
    },
    {
      "name": "CVE-2026-13772",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13772"
    },
    {
      "name": "CVE-2026-32141",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32141"
    },
    {
      "name": "CVE-2026-42037",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42037"
    },
    {
      "name": "CVE-2026-42042",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42042"
    },
    {
      "name": "CVE-2026-9071",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9071"
    },
    {
      "name": "CVE-2026-9006",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9006"
    },
    {
      "name": "CVE-2026-31898",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-31898"
    },
    {
      "name": "CVE-2026-24001",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24001"
    },
    {
      "name": "CVE-2023-24056",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-24056"
    },
    {
      "name": "CVE-2024-24786",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-24786"
    },
    {
      "name": "CVE-2026-10852",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10852"
    },
    {
      "name": "CVE-2026-27212",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27212"
    },
    {
      "name": "CVE-2025-12183",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-12183"
    },
    {
      "name": "CVE-2026-29063",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-29063"
    },
    {
      "name": "CVE-2025-68428",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68428"
    },
    {
      "name": "CVE-2025-13465",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-13465"
    },
    {
      "name": "CVE-2026-4926",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4926"
    },
    {
      "name": "CVE-2026-1718",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1718"
    },
    {
      "name": "CVE-2026-27904",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27904"
    }
  ],
  "initial_release_date": "2026-07-03T00:00:00",
  "last_revision_date": "2026-07-03T00:00:00",
  "links": [],
  "reference": "CERTFR-2026-AVI-0834",
  "revisions": [
    {
      "description": "Version initiale",
      "revision_date": "2026-07-03T00:00:00.000000"
    }
  ],
  "risks": [
    {
      "description": "D\u00e9ni de service \u00e0 distance"
    },
    {
      "description": "Injection de code indirecte \u00e0 distance (XSS)"
    },
    {
      "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
    },
    {
      "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
    },
    {
      "description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
    },
    {
      "description": "Falsification de requ\u00eates c\u00f4t\u00e9 serveur (SSRF)"
    },
    {
      "description": "Contournement de la politique de s\u00e9curit\u00e9"
    },
    {
      "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
    },
    {
      "description": "\u00c9l\u00e9vation de privil\u00e8ges"
    }
  ],
  "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits IBM. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance, une \u00e9l\u00e9vation de privil\u00e8ges et un d\u00e9ni de service \u00e0 distance.",
  "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits IBM",
  "vendor_advisories": [
    {
      "published_at": "2026-06-29",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7278360",
      "url": "https://www.ibm.com/support/pages/node/7278360"
    },
    {
      "published_at": "2026-07-02",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7279004",
      "url": "https://www.ibm.com/support/pages/node/7279004"
    },
    {
      "published_at": "2026-07-02",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7278998",
      "url": "https://www.ibm.com/support/pages/node/7278998"
    },
    {
      "published_at": "2026-07-02",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7278996",
      "url": "https://www.ibm.com/support/pages/node/7278996"
    },
    {
      "published_at": "2026-07-02",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7278993",
      "url": "https://www.ibm.com/support/pages/node/7278993"
    },
    {
      "published_at": "2026-07-02",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7279001",
      "url": "https://www.ibm.com/support/pages/node/7279001"
    },
    {
      "published_at": "2026-07-02",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7278935",
      "url": "https://www.ibm.com/support/pages/node/7278935"
    },
    {
      "published_at": "2026-06-30",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7278590",
      "url": "https://www.ibm.com/support/pages/node/7278590"
    },
    {
      "published_at": "2026-06-26",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7278148",
      "url": "https://www.ibm.com/support/pages/node/7278148"
    },
    {
      "published_at": "2026-07-02",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7279002",
      "url": "https://www.ibm.com/support/pages/node/7279002"
    },
    {
      "published_at": "2026-07-02",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7278995",
      "url": "https://www.ibm.com/support/pages/node/7278995"
    },
    {
      "published_at": "2026-07-02",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7278997",
      "url": "https://www.ibm.com/support/pages/node/7278997"
    },
    {
      "published_at": "2026-07-02",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7278990",
      "url": "https://www.ibm.com/support/pages/node/7278990"
    },
    {
      "published_at": "2026-06-29",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7278358",
      "url": "https://www.ibm.com/support/pages/node/7278358"
    },
    {
      "published_at": "2026-07-02",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7278989",
      "url": "https://www.ibm.com/support/pages/node/7278989"
    },
    {
      "published_at": "2026-06-30",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7278576",
      "url": "https://www.ibm.com/support/pages/node/7278576"
    },
    {
      "published_at": "2026-06-30",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7278572",
      "url": "https://www.ibm.com/support/pages/node/7278572"
    },
    {
      "published_at": "2026-06-30",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7278580",
      "url": "https://www.ibm.com/support/pages/node/7278580"
    },
    {
      "published_at": "2026-06-29",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7278398",
      "url": "https://www.ibm.com/support/pages/node/7278398"
    },
    {
      "published_at": "2026-06-29",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7278359",
      "url": "https://www.ibm.com/support/pages/node/7278359"
    },
    {
      "published_at": "2026-07-02",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7279003",
      "url": "https://www.ibm.com/support/pages/node/7279003"
    },
    {
      "published_at": "2026-06-26",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7278103",
      "url": "https://www.ibm.com/support/pages/node/7278103"
    },
    {
      "published_at": "2026-06-30",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7278593",
      "url": "https://www.ibm.com/support/pages/node/7278593"
    },
    {
      "published_at": "2026-06-29",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7278399",
      "url": "https://www.ibm.com/support/pages/node/7278399"
    }
  ]
}

CERTFR-2026-AVI-0810
Vulnerability from certfr_avis

De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

Solutions

Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

Impacted products
Vendor Product Description
IBM Sterling Partner Engagement Manager Essentials Edition Sterling Partner Engagement Manager versions 6.2.3.x antérieures à 6.2.3.6
IBM Sterling Sterling Secure Proxy versions 6.1.0.x antérieures à 6.1.0.4 iFix01
IBM N/A WebSphere Application Server sans le dernier correctif de sécurité
IBM Sterling Sterling Order Management sans le dernier correctif de sécurité
IBM N/A WebSphere Remote Server versions 9.0.x antérieures à 9.0.5.29
IBM QRadar QRadar DNS Analyzer App versions antérieures à 2.0.5
IBM N/A WebSphere Liberty Operator versions antérieures à 1.6.2
IBM Cloud Pak System Cloud Pak System versions antérieures à 2.3.5.1
IBM N/A WebSphere Remote Server versions 8.5.x antérieures à 8.5.5.30
IBM Sterling Sterling External Authentication Server versions 6.1.1.x antérieures à 6.1.1.3 iFix01
IBM Sterling Sterling Connect:Direct for Microsoft Windows versions 6.4.0.x antérieures à 6.4.0.4_iFix035
IBM Db2 Db2 versions V11.5 et V12.1 sans le dernier correctif de sécurité
IBM Sterling Sterling Connect:Direct for Microsoft Windows versions 6.3.0.x antérieures à 6.3.0.6_iFix062
IBM N/A WebSphere eXtreme Scale versions 8.6.x antérieures à 8.6.1 sans le correctif PH71616 iFix
IBM Sterling Sterling Secure Proxy versions 6.2.1.x antérieures à 6.2.1.2 iFix02
IBM Sterling Partner Engagement Manager Essentials Edition Sterling Partner Engagement Manager versions 6.2.4.x antérieures à 6.2.4.4
References
Bulletin de sécurité IBM 7277716 2026-06-24 vendor-advisory
Bulletin de sécurité IBM 7277692 2026-07-27 vendor-advisory
Bulletin de sécurité IBM 7277418 2026-06-23 vendor-advisory
Bulletin de sécurité IBM 7275595 2026-06-25 vendor-advisory
Bulletin de sécurité IBM 7277973 2026-06-25 vendor-advisory
Bulletin de sécurité IBM 7277546 2026-06-23 vendor-advisory
Bulletin de sécurité IBM 7277694 2026-06-24 vendor-advisory
Bulletin de sécurité IBM 7277531 2026-06-23 vendor-advisory
Bulletin de sécurité IBM 7277693 2026-06-24 vendor-advisory
Bulletin de sécurité IBM 7277544 2026-06-23 vendor-advisory
Bulletin de sécurité IBM 7277550 2026-06-23 vendor-advisory
Bulletin de sécurité IBM 7277424 2026-06-23 vendor-advisory
Bulletin de sécurité IBM 7277420 2026-06-23 vendor-advisory
Bulletin de sécurité IBM 7277742 2026-06-24 vendor-advisory
Bulletin de sécurité IBM 7277387 2026-06-22 vendor-advisory
Bulletin de sécurité IBM 7277556 2026-06-23 vendor-advisory
Bulletin de sécurité IBM 7277555 2026-06-23 vendor-advisory
Bulletin de sécurité IBM 7278112 2026-06-26 vendor-advisory
Bulletin de sécurité IBM 7277422 2026-08-12 vendor-advisory
Bulletin de sécurité IBM 7277536 2026-06-23 vendor-advisory
Bulletin de sécurité IBM 7277767 2026-06-24 vendor-advisory
Bulletin de sécurité IBM 7278103 2026-06-26 vendor-advisory

Show details on source website


{
  "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
  "affected_systems": [
    {
      "description": "Sterling Partner Engagement Manager versions 6.2.3.x ant\u00e9rieures \u00e0 6.2.3.6",
      "product": {
        "name": "Sterling Partner Engagement Manager Essentials Edition",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Sterling Secure Proxy versions 6.1.0.x ant\u00e9rieures \u00e0 6.1.0.4 iFix01",
      "product": {
        "name": "Sterling",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "WebSphere Application Server sans le dernier correctif de s\u00e9curit\u00e9",
      "product": {
        "name": "N/A",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Sterling Order Management sans le dernier correctif de s\u00e9curit\u00e9",
      "product": {
        "name": "Sterling",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "WebSphere Remote Server versions 9.0.x ant\u00e9rieures \u00e0 9.0.5.29",
      "product": {
        "name": "N/A",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "QRadar DNS Analyzer App versions ant\u00e9rieures \u00e0 2.0.5",
      "product": {
        "name": "QRadar",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "WebSphere Liberty Operator versions ant\u00e9rieures \u00e0 1.6.2",
      "product": {
        "name": "N/A",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Cloud Pak System versions ant\u00e9rieures \u00e0 2.3.5.1",
      "product": {
        "name": "Cloud Pak System",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "WebSphere Remote Server versions 8.5.x ant\u00e9rieures \u00e0 8.5.5.30",
      "product": {
        "name": "N/A",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Sterling External Authentication Server versions 6.1.1.x ant\u00e9rieures \u00e0 6.1.1.3 iFix01",
      "product": {
        "name": "Sterling",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Sterling Connect:Direct for Microsoft Windows versions 6.4.0.x ant\u00e9rieures \u00e0 6.4.0.4_iFix035",
      "product": {
        "name": "Sterling",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Db2 versions V11.5 et V12.1 sans le dernier correctif de s\u00e9curit\u00e9",
      "product": {
        "name": "Db2",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Sterling Connect:Direct for Microsoft Windows versions 6.3.0.x ant\u00e9rieures \u00e0 6.3.0.6_iFix062",
      "product": {
        "name": "Sterling",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "WebSphere eXtreme Scale versions 8.6.x ant\u00e9rieures \u00e0 8.6.1 sans le correctif PH71616 iFix",
      "product": {
        "name": "N/A",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Sterling Secure Proxy versions 6.2.1.x ant\u00e9rieures \u00e0 6.2.1.2 iFix02",
      "product": {
        "name": "Sterling",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Sterling Partner Engagement Manager versions 6.2.4.x ant\u00e9rieures \u00e0 6.2.4.4",
      "product": {
        "name": "Sterling Partner Engagement Manager Essentials Edition",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    }
  ],
  "affected_systems_content": "",
  "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
  "cves": [
    {
      "name": "CVE-2026-5588",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5588"
    },
    {
      "name": "CVE-2025-36353",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36353"
    },
    {
      "name": "CVE-2025-66199",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-66199"
    },
    {
      "name": "CVE-2026-33871",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33871"
    },
    {
      "name": "CVE-2025-2534",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-2534"
    },
    {
      "name": "CVE-2026-11383",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11383"
    },
    {
      "name": "CVE-2026-42041",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42041"
    },
    {
      "name": "CVE-2025-13867",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-13867"
    },
    {
      "name": "CVE-2026-42402",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42402"
    },
    {
      "name": "CVE-2025-2668",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-2668"
    },
    {
      "name": "CVE-2025-36427",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36427"
    },
    {
      "name": "CVE-2025-15469",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15469"
    },
    {
      "name": "CVE-2025-36131",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36131"
    },
    {
      "name": "CVE-2025-12084",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-12084"
    },
    {
      "name": "CVE-2024-47118",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-47118"
    },
    {
      "name": "CVE-2025-36098",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36098"
    },
    {
      "name": "CVE-2025-69419",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69419"
    },
    {
      "name": "CVE-2026-33814",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33814"
    },
    {
      "name": "CVE-2025-36184",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36184"
    },
    {
      "name": "CVE-2026-1605",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1605"
    },
    {
      "name": "CVE-2026-22013",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22013"
    },
    {
      "name": "CVE-2026-22018",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22018"
    },
    {
      "name": "CVE-2026-42580",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42580"
    },
    {
      "name": "CVE-2025-36247",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36247"
    },
    {
      "name": "CVE-2025-36009",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36009"
    },
    {
      "name": "CVE-2025-7962",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-7962"
    },
    {
      "name": "CVE-2025-15467",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15467"
    },
    {
      "name": "CVE-2026-33870",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33870"
    },
    {
      "name": "CVE-2025-36070",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36070"
    },
    {
      "name": "CVE-2026-0994",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0994"
    },
    {
      "name": "CVE-2025-36428",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36428"
    },
    {
      "name": "CVE-2025-41248",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-41248"
    },
    {
      "name": "CVE-2026-42585",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42585"
    },
    {
      "name": "CVE-2026-11541",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11541"
    },
    {
      "name": "CVE-2026-34282",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34282"
    },
    {
      "name": "CVE-2026-11707",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11707"
    },
    {
      "name": "CVE-2025-36387",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36387"
    },
    {
      "name": "CVE-2026-42036",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42036"
    },
    {
      "name": "CVE-2026-39821",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39821"
    },
    {
      "name": "CVE-2025-58057",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-58057"
    },
    {
      "name": "CVE-2026-11594",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11594"
    },
    {
      "name": "CVE-2026-42403",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42403"
    },
    {
      "name": "CVE-2026-22795",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22795"
    },
    {
      "name": "CVE-2026-10109",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10109"
    },
    {
      "name": "CVE-2026-27136",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27136"
    },
    {
      "name": "CVE-2023-47038",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-47038"
    },
    {
      "name": "CVE-2025-62718",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-62718"
    },
    {
      "name": "CVE-2025-36136",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36136"
    },
    {
      "name": "CVE-2026-42584",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42584"
    },
    {
      "name": "CVE-2025-36008",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36008"
    },
    {
      "name": "CVE-2026-23865",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23865"
    },
    {
      "name": "CVE-2026-5598",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5598"
    },
    {
      "name": "CVE-2026-42033",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42033"
    },
    {
      "name": "CVE-2026-42035",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42035"
    },
    {
      "name": "CVE-2026-11536",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11536"
    },
    {
      "name": "CVE-2025-69421",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69421"
    },
    {
      "name": "CVE-2026-34478",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34478"
    },
    {
      "name": "CVE-2026-42043",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42043"
    },
    {
      "name": "CVE-2025-11143",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-11143"
    },
    {
      "name": "CVE-2025-36006",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36006"
    },
    {
      "name": "CVE-2026-6918",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6918"
    },
    {
      "name": "CVE-2026-34480",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34480"
    },
    {
      "name": "CVE-2026-40175",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40175"
    },
    {
      "name": "CVE-2026-5795",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5795"
    },
    {
      "name": "CVE-2025-68161",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68161"
    },
    {
      "name": "CVE-2025-33012",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-33012"
    },
    {
      "name": "CVE-2026-42506",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42506"
    },
    {
      "name": "CVE-2026-34479",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34479"
    },
    {
      "name": "CVE-2026-22796",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22796"
    },
    {
      "name": "CVE-2026-42040",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42040"
    },
    {
      "name": "CVE-2026-1188",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1188"
    },
    {
      "name": "CVE-2026-25680",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25680"
    },
    {
      "name": "CVE-2025-55163",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-55163"
    },
    {
      "name": "CVE-2022-24729",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-24729"
    },
    {
      "name": "CVE-2025-36425",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36425"
    },
    {
      "name": "CVE-2026-10845",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10845"
    },
    {
      "name": "CVE-2025-12635",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-12635"
    },
    {
      "name": "CVE-2026-42404",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42404"
    },
    {
      "name": "CVE-2026-40895",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40895"
    },
    {
      "name": "CVE-2026-22016",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22016"
    },
    {
      "name": "CVE-2026-22021",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22021"
    },
    {
      "name": "CVE-2026-22007",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22007"
    },
    {
      "name": "CVE-2025-68160",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68160"
    },
    {
      "name": "CVE-2026-34268",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34268"
    },
    {
      "name": "CVE-2025-67735",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-67735"
    },
    {
      "name": "CVE-2024-29371",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-29371"
    },
    {
      "name": "CVE-2026-42038",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42038"
    },
    {
      "name": "CVE-2026-42583",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42583"
    },
    {
      "name": "CVE-2026-2332",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2332"
    },
    {
      "name": "CVE-2025-36001",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36001"
    },
    {
      "name": "CVE-2026-42039",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42039"
    },
    {
      "name": "CVE-2025-58056",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-58056"
    },
    {
      "name": "CVE-2026-8149",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8149"
    },
    {
      "name": "CVE-2026-42502",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42502"
    },
    {
      "name": "CVE-2026-42581",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42581"
    },
    {
      "name": "CVE-2025-40909",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-40909"
    },
    {
      "name": "CVE-2025-36365",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36365"
    },
    {
      "name": "CVE-2026-25681",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25681"
    },
    {
      "name": "CVE-2025-69418",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69418"
    },
    {
      "name": "CVE-2025-15468",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15468"
    },
    {
      "name": "CVE-2025-36442",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36442"
    },
    {
      "name": "CVE-2026-42044",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42044"
    },
    {
      "name": "CVE-2026-42034",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42034"
    },
    {
      "name": "CVE-2026-42587",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42587"
    },
    {
      "name": "CVE-2025-48924",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-48924"
    },
    {
      "name": "CVE-2024-47072",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-47072"
    },
    {
      "name": "CVE-2025-11187",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-11187"
    },
    {
      "name": "CVE-2025-41249",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-41249"
    },
    {
      "name": "CVE-2025-36366",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36366"
    },
    {
      "name": "CVE-2025-36123",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36123"
    },
    {
      "name": "CVE-2026-42264",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42264"
    },
    {
      "name": "CVE-2026-0636",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0636"
    },
    {
      "name": "CVE-2026-42037",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42037"
    },
    {
      "name": "CVE-2026-42042",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42042"
    },
    {
      "name": "CVE-2026-9006",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9006"
    },
    {
      "name": "CVE-2025-33134",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-33134"
    },
    {
      "name": "CVE-2026-11806",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11806"
    },
    {
      "name": "CVE-2026-34477",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34477"
    },
    {
      "name": "CVE-2025-46392",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-46392"
    },
    {
      "name": "CVE-2025-36407",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36407"
    },
    {
      "name": "CVE-2026-22008",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22008"
    },
    {
      "name": "CVE-2025-14813",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-14813"
    },
    {
      "name": "CVE-2025-69420",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69420"
    }
  ],
  "initial_release_date": "2026-06-26T00:00:00",
  "last_revision_date": "2026-06-26T00:00:00",
  "links": [],
  "reference": "CERTFR-2026-AVI-0810",
  "revisions": [
    {
      "description": "Version initiale",
      "revision_date": "2026-06-26T00:00:00.000000"
    }
  ],
  "risks": [
    {
      "description": "D\u00e9ni de service \u00e0 distance"
    },
    {
      "description": "Injection de code indirecte \u00e0 distance (XSS)"
    },
    {
      "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
    },
    {
      "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
    },
    {
      "description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
    },
    {
      "description": "Falsification de requ\u00eates c\u00f4t\u00e9 serveur (SSRF)"
    },
    {
      "description": "Contournement de la politique de s\u00e9curit\u00e9"
    },
    {
      "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
    },
    {
      "description": "\u00c9l\u00e9vation de privil\u00e8ges"
    }
  ],
  "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits IBM. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance, une \u00e9l\u00e9vation de privil\u00e8ges et un d\u00e9ni de service \u00e0 distance.",
  "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits IBM",
  "vendor_advisories": [
    {
      "published_at": "2026-06-24",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7277716",
      "url": "https://www.ibm.com/support/pages/node/7277716"
    },
    {
      "published_at": "2026-07-27",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7277692",
      "url": "https://www.ibm.com/support/pages/node/7277692"
    },
    {
      "published_at": "2026-06-23",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7277418",
      "url": "https://www.ibm.com/support/pages/node/7277418"
    },
    {
      "published_at": "2026-06-25",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7275595",
      "url": "https://www.ibm.com/support/pages/node/7275595"
    },
    {
      "published_at": "2026-06-25",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7277973",
      "url": "https://www.ibm.com/support/pages/node/7277973"
    },
    {
      "published_at": "2026-06-23",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7277546",
      "url": "https://www.ibm.com/support/pages/node/7277546"
    },
    {
      "published_at": "2026-06-24",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7277694",
      "url": "https://www.ibm.com/support/pages/node/7277694"
    },
    {
      "published_at": "2026-06-23",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7277531",
      "url": "https://www.ibm.com/support/pages/node/7277531"
    },
    {
      "published_at": "2026-06-24",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7277693",
      "url": "https://www.ibm.com/support/pages/node/7277693"
    },
    {
      "published_at": "2026-06-23",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7277544",
      "url": "https://www.ibm.com/support/pages/node/7277544"
    },
    {
      "published_at": "2026-06-23",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7277550",
      "url": "https://www.ibm.com/support/pages/node/7277550"
    },
    {
      "published_at": "2026-06-23",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7277424",
      "url": "https://www.ibm.com/support/pages/node/7277424"
    },
    {
      "published_at": "2026-06-23",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7277420",
      "url": "https://www.ibm.com/support/pages/node/7277420"
    },
    {
      "published_at": "2026-06-24",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7277742",
      "url": "https://www.ibm.com/support/pages/node/7277742"
    },
    {
      "published_at": "2026-06-22",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7277387",
      "url": "https://www.ibm.com/support/pages/node/7277387"
    },
    {
      "published_at": "2026-06-23",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7277556",
      "url": "https://www.ibm.com/support/pages/node/7277556"
    },
    {
      "published_at": "2026-06-23",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7277555",
      "url": "https://www.ibm.com/support/pages/node/7277555"
    },
    {
      "published_at": "2026-06-26",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7278112",
      "url": "https://www.ibm.com/support/pages/node/7278112"
    },
    {
      "published_at": "2026-08-12",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7277422",
      "url": "https://www.ibm.com/support/pages/node/7277422"
    },
    {
      "published_at": "2026-06-23",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7277536",
      "url": "https://www.ibm.com/support/pages/node/7277536"
    },
    {
      "published_at": "2026-06-24",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7277767",
      "url": "https://www.ibm.com/support/pages/node/7277767"
    },
    {
      "published_at": "2026-06-26",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7278103",
      "url": "https://www.ibm.com/support/pages/node/7278103"
    }
  ]
}

CERTFR-2026-AVI-0748
Vulnerability from certfr_avis

De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.

Solutions

Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

Impacted products
Vendor Product Description
IBM WebSphere WebSphere Service Registry and Repository version 8.5 sans les derniers correctifs de sécurité
IBM Sterling Connect:Direct Sterling Connect:Direct Web Services versions 6.4.x antérieures à 6.4.0.8
IBM WebSphere WebSphere Hybrid Edition version 5.1 sans les correctifs de sécurité PH71342, PH71422, PH71453 et PH71454
IBM Db2 Db2 Big SQL versions antérireures à 8.3.1 patch 4
IBM Sterling Connect:Direct Sterling Connect:Direct Web Services versions 6.3.x antérieures à 6.3.0.19
References
Bulletin de sécurité IBM 7275419 2026-06-08 vendor-advisory
Bulletin de sécurité IBM 7275252 2026-06-05 vendor-advisory
Bulletin de sécurité IBM 7275305 2026-06-06 vendor-advisory
Bulletin de sécurité IBM 7275468 2026-06-08 vendor-advisory
Bulletin de sécurité IBM 7275256 2026-06-05 vendor-advisory
Bulletin de sécurité IBM 7275462 2026-06-08 vendor-advisory
Bulletin de sécurité IBM 7275528 2026-06-08 vendor-advisory
Bulletin de sécurité IBM 7275257 2026-06-05 vendor-advisory
Bulletin de sécurité IBM 7275459 2026-06-08 vendor-advisory

Show details on source website


{
  "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
  "affected_systems": [
    {
      "description": "WebSphere Service Registry and Repository version 8.5 sans les derniers correctifs de s\u00e9curit\u00e9",
      "product": {
        "name": "WebSphere",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Sterling Connect:Direct Web Services versions 6.4.x ant\u00e9rieures \u00e0 6.4.0.8",
      "product": {
        "name": "Sterling Connect:Direct",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "WebSphere Hybrid Edition version 5.1 sans les correctifs de s\u00e9curit\u00e9 PH71342, PH71422, PH71453 et PH71454",
      "product": {
        "name": "WebSphere",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Db2 Big SQL versions ant\u00e9rireures \u00e0 8.3.1 patch 4",
      "product": {
        "name": "Db2",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Sterling Connect:Direct Web Services versions 6.3.x ant\u00e9rieures \u00e0 6.3.0.19",
      "product": {
        "name": "Sterling Connect:Direct",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    }
  ],
  "affected_systems_content": "",
  "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
  "cves": [
    {
      "name": "CVE-2026-40974",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40974"
    },
    {
      "name": "CVE-2026-9319",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9319"
    },
    {
      "name": "CVE-2025-62718",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-62718"
    },
    {
      "name": "CVE-2026-40971",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40971"
    },
    {
      "name": "CVE-2026-8644",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8644"
    },
    {
      "name": "CVE-2026-27903",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27903"
    },
    {
      "name": "CVE-2026-8620",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8620"
    },
    {
      "name": "CVE-2026-8633",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8633"
    },
    {
      "name": "CVE-2026-9330",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9330"
    },
    {
      "name": "CVE-2026-9311",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9311"
    },
    {
      "name": "CVE-2026-26996",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26996"
    },
    {
      "name": "CVE-2026-27904",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27904"
    }
  ],
  "initial_release_date": "2026-06-12T00:00:00",
  "last_revision_date": "2026-06-12T00:00:00",
  "links": [],
  "reference": "CERTFR-2026-AVI-0748",
  "revisions": [
    {
      "description": "Version initiale",
      "revision_date": "2026-06-12T00:00:00.000000"
    }
  ],
  "risks": [
    {
      "description": "D\u00e9ni de service \u00e0 distance"
    },
    {
      "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
    },
    {
      "description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
    },
    {
      "description": "Falsification de requ\u00eates c\u00f4t\u00e9 serveur (SSRF)"
    },
    {
      "description": "Contournement de la politique de s\u00e9curit\u00e9"
    },
    {
      "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
    }
  ],
  "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits IBM. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance, un d\u00e9ni de service \u00e0 distance et une atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es.",
  "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits IBM",
  "vendor_advisories": [
    {
      "published_at": "2026-06-08",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7275419",
      "url": "https://www.ibm.com/support/pages/node/7275419"
    },
    {
      "published_at": "2026-06-05",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7275252",
      "url": "https://www.ibm.com/support/pages/node/7275252"
    },
    {
      "published_at": "2026-06-06",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7275305",
      "url": "https://www.ibm.com/support/pages/node/7275305"
    },
    {
      "published_at": "2026-06-08",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7275468",
      "url": "https://www.ibm.com/support/pages/node/7275468"
    },
    {
      "published_at": "2026-06-05",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7275256",
      "url": "https://www.ibm.com/support/pages/node/7275256"
    },
    {
      "published_at": "2026-06-08",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7275462",
      "url": "https://www.ibm.com/support/pages/node/7275462"
    },
    {
      "published_at": "2026-06-08",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7275528",
      "url": "https://www.ibm.com/support/pages/node/7275528"
    },
    {
      "published_at": "2026-06-05",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7275257",
      "url": "https://www.ibm.com/support/pages/node/7275257"
    },
    {
      "published_at": "2026-06-08",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7275459",
      "url": "https://www.ibm.com/support/pages/node/7275459"
    }
  ]
}

CERTFR-2026-AVI-0641
Vulnerability from certfr_avis

De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

Solutions

Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

Impacted products
Vendor Product Description
IBM AIX Open SDK pour Rust sur AIX versions 1.92.x sans le correctif de sécurité Fix Pack 2
IBM WebSphere WebSphere Automation versions 1.1x antérieures à 1.12.1
IBM Db2 Db2 versions 12.1.x antérieures à 12.1.4 sans le correctif Special Build #83501
IBM Db2 Db2 Big SQL versions 7.6.x à 8.3.x antérieures à 8.3.1 patch 4
IBM Db2 Db2 sur Cloud Pak for Data et Db2 Warehouse sur Cloud Pak for Data versions 4.8.x à 5.3.x antérieures à 5.3.1
IBM AIX Open SDK pour Rust sur AIX versions 1.90.x sans le correctif de sécurité Fix Pack 2
IBM Sterling Sterling Transformation Extender versions 11.0.1.1 et 11.0.2.0 sans le correctif de sécurité PH71227
IBM Db2 Db2 versions 11.5.x antérieures à 11.5.9 sans le correctif Special Build #81937
References
Bulletin de sécurité IBM 7273152 2026-05-15 vendor-advisory
Bulletin de sécurité IBM 7273312 2026-05-18 vendor-advisory
Bulletin de sécurité IBM 7273153 2026-05-15 vendor-advisory
Bulletin de sécurité IBM 7273155 2026-05-15 vendor-advisory
Bulletin de sécurité IBM 7271877 2026-05-19 vendor-advisory
Bulletin de sécurité IBM 7273156 2026-05-15 vendor-advisory
Bulletin de sécurité IBM 7273269 2026-05-17 vendor-advisory
Bulletin de sécurité IBM 7273281 2026-05-18 vendor-advisory
Bulletin de sécurité IBM 7273150 2026-05-15 vendor-advisory
Bulletin de sécurité IBM 7273151 2026-05-15 vendor-advisory
Bulletin de sécurité IBM 7273555 2026-05-21 vendor-advisory

Show details on source website


{
  "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
  "affected_systems": [
    {
      "description": "Open SDK pour Rust sur AIX versions 1.92.x sans le correctif de s\u00e9curit\u00e9 Fix Pack 2",
      "product": {
        "name": "AIX",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "WebSphere Automation versions 1.1x ant\u00e9rieures \u00e0 1.12.1",
      "product": {
        "name": "WebSphere",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Db2 versions 12.1.x ant\u00e9rieures \u00e0 12.1.4 sans le correctif Special Build #83501",
      "product": {
        "name": "Db2",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Db2 Big SQL versions 7.6.x \u00e0 8.3.x ant\u00e9rieures \u00e0 8.3.1 patch 4",
      "product": {
        "name": "Db2",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Db2 sur Cloud Pak for Data et Db2 Warehouse sur Cloud Pak for Data versions 4.8.x \u00e0 5.3.x ant\u00e9rieures \u00e0 5.3.1",
      "product": {
        "name": "Db2",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Open SDK pour Rust sur AIX versions 1.90.x sans le correctif de s\u00e9curit\u00e9 Fix Pack 2",
      "product": {
        "name": "AIX",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Sterling Transformation Extender versions 11.0.1.1 et 11.0.2.0 sans le correctif de s\u00e9curit\u00e9 PH71227",
      "product": {
        "name": "Sterling",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    },
    {
      "description": "Db2 versions 11.5.x ant\u00e9rieures \u00e0 11.5.9 sans le correctif Special Build #81937",
      "product": {
        "name": "Db2",
        "vendor": {
          "name": "IBM",
          "scada": false
        }
      }
    }
  ],
  "affected_systems_content": "",
  "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
  "cves": [
    {
      "name": "CVE-2025-6395",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-6395"
    },
    {
      "name": "CVE-2026-26007",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26007"
    },
    {
      "name": "CVE-2025-61730",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-61730"
    },
    {
      "name": "CVE-2025-36353",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36353"
    },
    {
      "name": "CVE-2026-21933",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21933"
    },
    {
      "name": "CVE-2026-21932",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21932"
    },
    {
      "name": "CVE-2025-58190",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-58190"
    },
    {
      "name": "CVE-2026-32597",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32597"
    },
    {
      "name": "CVE-2026-31958",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-31958"
    },
    {
      "name": "CVE-2025-67726",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-67726"
    },
    {
      "name": "CVE-2026-33186",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33186"
    },
    {
      "name": "CVE-2025-13867",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-13867"
    },
    {
      "name": "CVE-2025-2668",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-2668"
    },
    {
      "name": "CVE-2025-36427",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36427"
    },
    {
      "name": "CVE-2025-39761",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-39761"
    },
    {
      "name": "CVE-2026-35611",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35611"
    },
    {
      "name": "CVE-2024-45310",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-45310"
    },
    {
      "name": "CVE-2025-36384",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36384"
    },
    {
      "name": "CVE-2025-36098",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36098"
    },
    {
      "name": "CVE-2025-36184",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36184"
    },
    {
      "name": "CVE-2026-2391",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2391"
    },
    {
      "name": "CVE-2026-22013",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22013"
    },
    {
      "name": "CVE-2026-22018",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22018"
    },
    {
      "name": "CVE-2025-36247",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36247"
    },
    {
      "name": "CVE-2025-58767",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-58767"
    },
    {
      "name": "CVE-2025-36009",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36009"
    },
    {
      "name": "CVE-2025-9820",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-9820"
    },
    {
      "name": "CVE-2025-36070",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36070"
    },
    {
      "name": "CVE-2025-36428",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36428"
    },
    {
      "name": "CVE-2025-15284",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15284"
    },
    {
      "name": "CVE-2026-34282",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34282"
    },
    {
      "name": "CVE-2025-36424",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36424"
    },
    {
      "name": "CVE-2025-36387",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36387"
    },
    {
      "name": "CVE-2025-33042",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-33042"
    },
    {
      "name": "CVE-2025-58057",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-58057"
    },
    {
      "name": "CVE-2026-21925",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21925"
    },
    {
      "name": "CVE-2025-64718",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-64718"
    },
    {
      "name": "CVE-2023-47038",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-47038"
    },
    {
      "name": "CVE-2025-62718",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-62718"
    },
    {
      "name": "CVE-2026-27142",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27142"
    },
    {
      "name": "CVE-2026-23865",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23865"
    },
    {
      "name": "CVE-2026-33671",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33671"
    },
    {
      "name": "CVE-2025-67721",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-67721"
    },
    {
      "name": "CVE-2026-33750",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33750"
    },
    {
      "name": "CVE-2026-6918",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6918"
    },
    {
      "name": "CVE-2025-47911",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-47911"
    },
    {
      "name": "CVE-2026-33228",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33228"
    },
    {
      "name": "CVE-2026-40175",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40175"
    },
    {
      "name": "CVE-2026-29045",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-29045"
    },
    {
      "name": "CVE-2021-43784",
      "url": "https://www.cve.org/CVERecord?id=CVE-2021-43784"
    },
    {
      "name": "CVE-2025-68161",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68161"
    },
    {
      "name": "CVE-2025-12801",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-12801"
    },
    {
      "name": "CVE-2026-1188",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1188"
    },
    {
      "name": "CVE-2026-27903",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27903"
    },
    {
      "name": "CVE-2026-41681",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41681"
    },
    {
      "name": "CVE-2026-25679",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25679"
    },
    {
      "name": "CVE-2025-55163",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-55163"
    },
    {
      "name": "CVE-2026-41677",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41677"
    },
    {
      "name": "CVE-2025-32990",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-32990"
    },
    {
      "name": "CVE-2025-36425",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36425"
    },
    {
      "name": "CVE-2025-32989",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-32989"
    },
    {
      "name": "CVE-2025-61594",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-61594"
    },
    {
      "name": "CVE-2026-22016",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22016"
    },
    {
      "name": "CVE-2026-22021",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22021"
    },
    {
      "name": "CVE-2026-22007",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22007"
    },
    {
      "name": "CVE-2025-54410",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-54410"
    },
    {
      "name": "CVE-2025-69873",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69873"
    },
    {
      "name": "CVE-2026-34268",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34268"
    },
    {
      "name": "CVE-2026-3713",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3713"
    },
    {
      "name": "CVE-2025-67735",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-67735"
    },
    {
      "name": "CVE-2025-61728",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-61728"
    },
    {
      "name": "CVE-2025-36001",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36001"
    },
    {
      "name": "CVE-2025-58056",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-58056"
    },
    {
      "name": "CVE-2025-32988",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-32988"
    },
    {
      "name": "CVE-2026-33672",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33672"
    },
    {
      "name": "CVE-2025-58181",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-58181"
    },
    {
      "name": "CVE-2025-47914",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-47914"
    },
    {
      "name": "CVE-2025-36365",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36365"
    },
    {
      "name": "CVE-2026-25639",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25639"
    },
    {
      "name": "CVE-2025-36442",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36442"
    },
    {
      "name": "CVE-2025-38351",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-38351"
    },
    {
      "name": "CVE-2026-21945",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21945"
    },
    {
      "name": "CVE-2025-59059",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59059"
    },
    {
      "name": "CVE-2026-41676",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41676"
    },
    {
      "name": "CVE-2025-14689",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-14689"
    },
    {
      "name": "CVE-2025-48924",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-48924"
    },
    {
      "name": "CVE-2025-8916",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-8916"
    },
    {
      "name": "CVE-2024-47072",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-47072"
    },
    {
      "name": "CVE-2025-36366",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36366"
    },
    {
      "name": "CVE-2025-36123",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36123"
    },
    {
      "name": "CVE-2026-26996",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26996"
    },
    {
      "name": "CVE-2025-68121",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68121"
    },
    {
      "name": "CVE-2024-50301",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-50301"
    },
    {
      "name": "CVE-2025-67724",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-67724"
    },
    {
      "name": "CVE-2025-61726",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-61726"
    },
    {
      "name": "CVE-2026-29087",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-29087"
    },
    {
      "name": "CVE-2025-21614",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-21614"
    },
    {
      "name": "CVE-2025-53864",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-53864"
    },
    {
      "name": "CVE-2026-32141",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32141"
    },
    {
      "name": "CVE-2026-35554",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35554"
    },
    {
      "name": "CVE-2025-5914",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-5914"
    },
    {
      "name": "CVE-2025-53057",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-53057"
    },
    {
      "name": "CVE-2025-36407",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36407"
    },
    {
      "name": "CVE-2026-29063",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-29063"
    },
    {
      "name": "CVE-2026-22008",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22008"
    },
    {
      "name": "CVE-2025-53066",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-53066"
    },
    {
      "name": "CVE-2026-1718",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1718"
    },
    {
      "name": "CVE-2025-22227",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-22227"
    },
    {
      "name": "CVE-2025-27221",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-27221"
    },
    {
      "name": "CVE-2026-27904",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27904"
    },
    {
      "name": "CVE-2026-24281",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24281"
    },
    {
      "name": "CVE-2026-41678",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41678"
    },
    {
      "name": "CVE-2025-14831",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-14831"
    }
  ],
  "initial_release_date": "2026-05-22T00:00:00",
  "last_revision_date": "2026-05-22T00:00:00",
  "links": [],
  "reference": "CERTFR-2026-AVI-0641",
  "revisions": [
    {
      "description": "Version initiale",
      "revision_date": "2026-05-22T00:00:00.000000"
    }
  ],
  "risks": [
    {
      "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
    },
    {
      "description": "\u00c9l\u00e9vation de privil\u00e8ges"
    },
    {
      "description": "D\u00e9ni de service \u00e0 distance"
    },
    {
      "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
    },
    {
      "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
    },
    {
      "description": "Contournement de la politique de s\u00e9curit\u00e9"
    },
    {
      "description": "Injection de code indirecte \u00e0 distance (XSS)"
    },
    {
      "description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
    },
    {
      "description": "Falsification de requ\u00eates c\u00f4t\u00e9 serveur (SSRF)"
    }
  ],
  "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits IBM. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance, une \u00e9l\u00e9vation de privil\u00e8ges et un d\u00e9ni de service \u00e0 distance.",
  "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits IBM",
  "vendor_advisories": [
    {
      "published_at": "2026-05-15",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7273152",
      "url": "https://www.ibm.com/support/pages/node/7273152"
    },
    {
      "published_at": "2026-05-18",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7273312",
      "url": "https://www.ibm.com/support/pages/node/7273312"
    },
    {
      "published_at": "2026-05-15",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7273153",
      "url": "https://www.ibm.com/support/pages/node/7273153"
    },
    {
      "published_at": "2026-05-15",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7273155",
      "url": "https://www.ibm.com/support/pages/node/7273155"
    },
    {
      "published_at": "2026-05-19",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7271877",
      "url": "https://www.ibm.com/support/pages/node/7271877"
    },
    {
      "published_at": "2026-05-15",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7273156",
      "url": "https://www.ibm.com/support/pages/node/7273156"
    },
    {
      "published_at": "2026-05-17",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7273269",
      "url": "https://www.ibm.com/support/pages/node/7273269"
    },
    {
      "published_at": "2026-05-18",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7273281",
      "url": "https://www.ibm.com/support/pages/node/7273281"
    },
    {
      "published_at": "2026-05-15",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7273150",
      "url": "https://www.ibm.com/support/pages/node/7273150"
    },
    {
      "published_at": "2026-05-15",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7273151",
      "url": "https://www.ibm.com/support/pages/node/7273151"
    },
    {
      "published_at": "2026-05-21",
      "title": "Bulletin de s\u00e9curit\u00e9 IBM 7273555",
      "url": "https://www.ibm.com/support/pages/node/7273555"
    }
  ]
}

CVE-2026-10534 (GCVE-0-2026-10534)
Vulnerability from cvelistv5
Published
2026-08-12 21:24
Modified
2026-08-13 13:36
CWE
  • CWE-121 - Stack-based Buffer Overflow
Summary
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF IMPORT parser.
References
Impacted products
Vendor Product Version
IBM Db2 Version: 11.5.0    11.5.9
Version: 12.1.0    12.1.5
    cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:12.1.5:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-10534",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-08-13T13:35:55.780915Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-08-13T13:36:04.909Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:12.1.5:*:*:*:*:*:*:*"
          ],
          "product": "Db2",
          "vendor": "IBM",
          "versions": [
            {
              "lessThanOrEqual": "11.5.9",
              "status": "affected",
              "version": "11.5.0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "12.1.5",
              "status": "affected",
              "version": "12.1.0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eIBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF IMPORT parser.\u003c/p\u003e"
            }
          ],
          "value": "IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF IMPORT parser."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 8.4,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-121",
              "description": "CWE-121 Stack-based Buffer Overflow",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-12T21:24:30.681Z",
        "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "shortName": "ibm"
      },
      "references": [
        {
          "tags": [
            "vendor-advisory",
            "patch"
          ],
          "url": "https://www.ibm.com/support/pages/node/7279461"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eCustomers running any vulnerable affected level of an affected Program, V11.5, and V12.1, can download the security update containing the interim fix for this issue from Fix Central. These security updates are available based on the most recent level for each impacted release: V11.5.9, V12.1.4, and V12.1.5. They can be applied to any affected level of the appropriate release to remediate this vulnerability.\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\u003cstrong\u003eRelease\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eFixed in mod pack\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eAPAR\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eDownload URL\u003c/strong\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eV11.5\u003c/td\u003e\u003ctd\u003eTBD\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/defect/aCIgJ000000ECHR/dt471716\" rel=\"nofollow\"\u003eDT471716\u003c/a\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eSecurity Update #87984 or later for V11.5.9 available at this link:\u003cbr/\u003e\u003ca href=\"https://www.ibm.com/support/pages/node/7087189\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/pages/node/7087189\u003c/a\u003e\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eV12.1\u003c/td\u003e\u003ctd\u003eTBD\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/defect/aCIgJ000000ECHR/dt471716\" rel=\"nofollow\"\u003eDT471716\u003c/a\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eSecurity Update #86025 or later for V12.1.4 available at this link:\u003cbr/\u003e\u003ca href=\"https://www.ibm.com/support/pages/node/7267513\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/pages/node/7267513\u003c/a\u003e\u003c/p\u003e\u003cp\u003eSecurity Update #88454 or later for V12.1.5 available at this link:\u003cbr/\u003e\u003ca href=\"https://www.ibm.com/support/pages/node/7282633\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/pages/node/7282633\u003c/a\u003e\u003cbr/\u003e\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003cp\u003e\u003c/p\u003e\u003cp\u003eIBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability.\u003c/p\u003e"
            }
          ],
          "value": "Customers running any vulnerable affected level of an affected Program, V11.5, and V12.1, can download the security update containing the interim fix for this issue from Fix Central. These security updates are available based on the most recent level for each impacted release: V11.5.9, V12.1.4, and V12.1.5. They can be applied to any affected level of the appropriate release to remediate this vulnerability.\n\n\n\n\n\nReleaseFixed in mod packAPARDownload URLV11.5TBD https://www.ibm.com/support/pages/node/7087189 \n\nV12.1TBD https://www.ibm.com/support/pages/node/7267513 \n\n\n\nSecurity Update #88454 or later for V12.1.5 available at this link:\n https://www.ibm.com/support/pages/node/7282633 \n\n\n\n\n\n\n\n\n\n\nIBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability."
        }
      ],
      "title": "IBM\u00ae Db2\u00ae is vulnerable to buffer overflow in the IXF IMPORT parser"
    }
  },
  "cveMetadata": {
    "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
    "assignerShortName": "ibm",
    "cveId": "CVE-2026-10534",
    "datePublished": "2026-08-12T21:24:30.681Z",
    "dateReserved": "2026-06-01T11:37:47.417Z",
    "dateUpdated": "2026-08-13T13:36:04.909Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-10543 (GCVE-0-2026-10543)
Vulnerability from cvelistv5
Published
2026-08-12 20:50
Modified
2026-08-13 13:53
CWE
Summary
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to privilege escalation with a specially crafted query.
References
Impacted products
Vendor Product Version
IBM Db2 Version: 11.5.0    11.5.9
Version: 12.1.0    12.1.5
    cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:12.1.5:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-10543",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-08-13T13:53:15.999423Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-08-13T13:53:30.464Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:12.1.5:*:*:*:*:*:*:*"
          ],
          "product": "Db2",
          "vendor": "IBM",
          "versions": [
            {
              "lessThanOrEqual": "11.5.9",
              "status": "affected",
              "version": "11.5.0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "12.1.5",
              "status": "affected",
              "version": "12.1.0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "This vulnerability was reported to IBM by Nicolas Verdier, Amazon."
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eIBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to privilege escalation with a specially crafted query.\u003c/p\u003e"
            }
          ],
          "value": "IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to privilege escalation with a specially crafted query."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-285",
              "description": "CWE-285 Improper Authorization",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-12T20:50:02.003Z",
        "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "shortName": "ibm"
      },
      "references": [
        {
          "tags": [
            "vendor-advisory",
            "patch"
          ],
          "url": "https://www.ibm.com/support/pages/node/7282949"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eCustomers running any vulnerable affected level of an affected Program, V11.5, and V12.1, can download the security update containing the interim fix for this issue from Fix Central. These security updates are available based on the most recent level for each impacted release: V11.5.9, V12.1.4 and V12.1.5. They can be applied to any affected level of the appropriate release to remediate this vulnerability.\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\u003cstrong\u003eRelease\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eFixed in mod pack\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eAPAR\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eDownload URL\u003c/strong\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eV11.5\u003c/td\u003e\u003ctd\u003eTBD\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/defect/aCIgJ000000EMa9/dt472016\" rel=\"nofollow\"\u003eDT472016\u003c/a\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eSecurity Update #87984 or later for V11.5.9 available at this link:\u003cbr/\u003e\u003ca href=\"https://www.ibm.com/support/pages/node/7087189\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/pages/node/7087189\u003c/a\u003e\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003e\u003cp\u003eV12.1\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eTBD\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/defect/aCIgJ000000EMa9/dt472016\" rel=\"nofollow\"\u003eDT472016\u003c/a\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eSecurity Update #87349 or later for V12.1.4 available at this link:\u003cbr/\u003e\u003ca href=\"https://www.ibm.com/support/pages/node/7267513\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/pages/node/7267513\u003c/a\u003e\u003c/p\u003e\u003cp\u003eSecurity Update #88454 or later for V12.1.5 available at this link:\u003cbr/\u003e\u003ca href=\"https://www.ibm.com/support/pages/node/7282633\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/pages/node/7282633\u003c/a\u003e\u003cbr/\u003e\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003cp\u003eNote: This remediation comes with multiple changes to Db2 functionality that are outlined here:\u003c/p\u003e\u003cul\u003e\u003cli\u003e\u003ca href=\"https://www.ibm.com/docs/en/db2/12.1.x?topic=statements-transfer-ownership\" rel=\"nofollow\"\u003eTRANSFER OWNERSHIP statement\u003c/a\u003e\u003c/li\u003e\u003cli\u003e\u003ca href=\"https://www.ibm.com/docs/en/db2/12.1.x?topic=variables-miscellaneous\" rel=\"nofollow\"\u003eNew DB2_TRANSFER_OWNER_RULES and DB2_TRANSFER_ALLOW_UNHELD_AUTHS registry variables\u003c/a\u003e\u003c/li\u003e\u003cli\u003e\u003ca href=\"https://www.ibm.com/docs/en/db2/12.1.x?topic=procedure-admin-move-table-move-tables-online\" rel=\"nofollow\"\u003eADMIN_MOVE_TABLE procedure\u003c/a\u003e\u003c/li\u003e\u003cli\u003e\u003ca href=\"https://www.ibm.com/docs/en/db2/12.1.x?topic=procedure-admin-copy-schema-copy-schema\" rel=\"nofollow\"\u003eADMIN_COPY_SCHEMA procedure\u003c/a\u003e\u003c/li\u003e\u003cli\u003e\u003ca href=\"https://www.ibm.com/docs/en/db2/12.1.x?topic=views-altobj-alter-table\" rel=\"nofollow\"\u003eALTOBJ procedure\u003c/a\u003e\u003c/li\u003e\u003c/ul\u003e\u003cp\u003eIBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability.\u003c/p\u003e"
            }
          ],
          "value": "Customers running any vulnerable affected level of an affected Program, V11.5, and V12.1, can download the security update containing the interim fix for this issue from Fix Central. These security updates are available based on the most recent level for each impacted release: V11.5.9, V12.1.4 and V12.1.5. They can be applied to any affected level of the appropriate release to remediate this vulnerability.\n\n\n\n\n\nReleaseFixed in mod packAPARDownload URLV11.5TBD https://www.ibm.com/support/pages/node/7087189 \n\n\n\nV12.1\n\n\n\nTBD\n\n\n\n https://www.ibm.com/support/pages/node/7267513 \n\n\n\nSecurity Update #88454 or later for V12.1.5 available at this link:\n https://www.ibm.com/support/pages/node/7282633 \n\n\n\n\n\n\nNote: This remediation comes with multiple changes to Db2 functionality that are outlined here:\n\n  *   TRANSFER OWNERSHIP statement https://www.ibm.com/docs/en/db2/12.1.x \n  *   New DB2_TRANSFER_OWNER_RULES and DB2_TRANSFER_ALLOW_UNHELD_AUTHS registry variables https://www.ibm.com/docs/en/db2/12.1.x \n  *   ADMIN_MOVE_TABLE procedure https://www.ibm.com/docs/en/db2/12.1.x \n  *   ADMIN_COPY_SCHEMA procedure https://www.ibm.com/docs/en/db2/12.1.x \n  *   ALTOBJ procedure https://www.ibm.com/docs/en/db2/12.1.x \n\n\n\n\nIBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability."
        }
      ],
      "title": "IBM\u00ae Db2\u00ae is vulnerable to privilege escalation with a specially crafted query"
    }
  },
  "cveMetadata": {
    "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
    "assignerShortName": "ibm",
    "cveId": "CVE-2026-10543",
    "datePublished": "2026-08-12T20:50:02.003Z",
    "dateReserved": "2026-06-01T12:41:02.957Z",
    "dateUpdated": "2026-08-13T13:53:30.464Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-16480 (GCVE-0-2026-16480)
Vulnerability from cvelistv5
Published
2026-08-12 20:49
Modified
2026-08-13 13:42
CWE
  • CWE-602 - Client-Side Enforcement of Server-Side Security
Summary
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is affected by an improper authorization vulnerability in the certain command, allowing a non-privileged user to bypass authority checks and modify database catalog data.
References
Impacted products
Vendor Product Version
IBM Db2 Version: 11.5.0    11.5.9
Version: 12.1.0    12.1.5
    cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:12.1.5:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-16480",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-08-13T13:41:36.860639Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-08-13T13:42:37.356Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:12.1.5:*:*:*:*:*:*:*"
          ],
          "product": "Db2",
          "vendor": "IBM",
          "versions": [
            {
              "lessThanOrEqual": "11.5.9",
              "status": "affected",
              "version": "11.5.0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "12.1.5",
              "status": "affected",
              "version": "12.1.0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eIBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is affected by an improper authorization vulnerability in the certain command, allowing a non-privileged user to bypass authority checks and modify database catalog data.\u003c/p\u003e"
            }
          ],
          "value": "IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is affected by an improper authorization vulnerability in the certain command, allowing a non-privileged user to bypass authority checks and modify database catalog data."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-602",
              "description": "CWE-602 Client-Side Enforcement of Server-Side Security",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-12T20:49:02.220Z",
        "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "shortName": "ibm"
      },
      "references": [
        {
          "tags": [
            "vendor-advisory",
            "patch"
          ],
          "url": "https://www.ibm.com/support/pages/node/7282951"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eCustomers running any vulnerable affected level of an affected Program, V11.5, and V12.1, can download the security update containing the interim fix for this issue from Fix Central. These security updates are available based on the most recent level for each impacted release: V11.5.9, V12.1.4 and V12.1.5. They can be applied to any affected level of the appropriate release to remediate this vulnerability.\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\u003cstrong\u003eRelease\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eFixed in mod pack\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eAPAR\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eDownload URL\u003c/strong\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eV11.5\u003c/td\u003e\u003ctd\u003eTBD\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/defect/aCIgJ000000FXGb/dt474728\" rel=\"nofollow\"\u003eDT474728\u003c/a\u003e\u003c/td\u003e\u003ctd\u003eSecurity Update #87984 or later for V11.5.9 available at this link:\u003cbr/\u003e\u003ca href=\"https://www.ibm.com/support/pages/node/7087189\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/pages/node/7087189\u003c/a\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003e\u003cp\u003eV12.1\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eTBD\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/defect/aCIgJ000000FXGb/dt474728\" rel=\"nofollow\"\u003eDT474728\u003c/a\u003e\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eSecurity Update #86025 or later for V12.1.4 available at this link:\u003cbr/\u003e\u003ca href=\"https://www.ibm.com/support/pages/node/7267513\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/pages/node/7267513\u003c/a\u003e\u003c/p\u003e\u003cp\u003eSecurity Update #88454 or later for V12.1.5 available at this link:\u003cbr/\u003e\u003ca href=\"https://www.ibm.com/support/pages/node/7282633\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/pages/node/7282633\u003c/a\u003e\u003cbr/\u003e\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003cp\u003e\u003c/p\u003e\u003cp\u003eIBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability.\u003c/p\u003e"
            }
          ],
          "value": "Customers running any vulnerable affected level of an affected Program, V11.5, and V12.1, can download the security update containing the interim fix for this issue from Fix Central. These security updates are available based on the most recent level for each impacted release: V11.5.9, V12.1.4 and V12.1.5. They can be applied to any affected level of the appropriate release to remediate this vulnerability.\n\n\n\n\n\nReleaseFixed in mod packAPARDownload URLV11.5TBD https://www.ibm.com/support/pages/node/7087189 \n\nV12.1\n\n\n\n\n\n\n\nTBD\n\n\n\n\n\n\n\n https://www.ibm.com/support/pages/node/7267513 \n\n\n\nSecurity Update #88454 or later for V12.1.5 available at this link:\n https://www.ibm.com/support/pages/node/7282633 \n\n\n\n\n\n\n\n\n\n\nIBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability."
        }
      ],
      "title": "IBM\u00ae Db2\u00ae is affected by an improper authorization vulnerability in the certain command, allowing a non-privileged user to bypass authority checks and modify database catalog data."
    }
  },
  "cveMetadata": {
    "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
    "assignerShortName": "ibm",
    "cveId": "CVE-2026-16480",
    "datePublished": "2026-08-12T20:49:02.220Z",
    "dateReserved": "2026-07-21T14:34:45.978Z",
    "dateUpdated": "2026-08-13T13:42:37.356Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-18097 (GCVE-0-2026-18097)
Vulnerability from cvelistv5
Published
2026-08-12 20:48
Modified
2026-08-14 22:14
CWE
  • CWE-532 - Insertion of Sensitive Information into Log File
Summary
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to obtain sensitive information due to the logging of plain text passwords in trace files.
References
Impacted products
Vendor Product Version
IBM Db2 Version: 11.5.0    11.5.9
Version: 12.1.0    12.1.5
    cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:12.1.5:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-18097",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-08-14T22:14:27.437283Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-08-14T22:14:38.325Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:12.1.5:*:*:*:*:*:*:*"
          ],
          "product": "Db2",
          "vendor": "IBM",
          "versions": [
            {
              "lessThanOrEqual": "11.5.9",
              "status": "affected",
              "version": "11.5.0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "12.1.5",
              "status": "affected",
              "version": "12.1.0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eIBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to obtain sensitive information due to the logging of plain text passwords in trace files.\u003c/p\u003e"
            }
          ],
          "value": "IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to obtain sensitive information due to the logging of plain text passwords in trace files."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "NONE",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-532",
              "description": "CWE-532 Insertion of Sensitive Information into Log File",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-12T20:48:29.761Z",
        "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "shortName": "ibm"
      },
      "references": [
        {
          "tags": [
            "vendor-advisory",
            "patch"
          ],
          "url": "https://www.ibm.com/support/pages/node/7282952"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eCustomers running any vulnerable affected level of an affected Program, V11.5, and V12.1, can download the security update containing the interim fix for this issue from Fix Central. These security updates are available based on the most recent level for each impacted release: V11.5.9, V12.1.4 and V12.1.5. They can be applied to any affected level of the appropriate release to remediate this vulnerability.\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\u003cstrong\u003eRelease\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eFixed in mod pack\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eAPAR\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eDownload URL\u003c/strong\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eV11.5\u003c/td\u003e\u003ctd\u003eTBD\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/defect/aCIgJ000000FtVd/dt475590\" rel=\"nofollow\"\u003eDT475590\u003c/a\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eSecurity Update #87984 or later for V11.5.9 available at this link:\u003cbr/\u003e\u003ca href=\"https://www.ibm.com/support/pages/node/7087189\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/pages/node/7087189\u003c/a\u003e\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003e\u003cp\u003eV12.1\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eTBD\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/defect/aCIgJ000000FtVd/dt475590\" rel=\"nofollow\"\u003eDT475590\u003c/a\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eSecurity Update #86025 or later for V12.1.4 available at this link:\u003cbr/\u003e\u003ca href=\"https://www.ibm.com/support/pages/node/7267513\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/pages/node/7267513\u003c/a\u003e\u003c/p\u003e\u003cp\u003eSecurity Update #88454 or later for V12.1.5 available at this link:\u003cbr/\u003e\u003ca href=\"https://www.ibm.com/support/pages/node/7282633\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/pages/node/7282633\u003c/a\u003e\u003cbr/\u003e\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003cp\u003e\u003c/p\u003e\u003cp\u003eIBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability.\u003c/p\u003e"
            }
          ],
          "value": "Customers running any vulnerable affected level of an affected Program, V11.5, and V12.1, can download the security update containing the interim fix for this issue from Fix Central. These security updates are available based on the most recent level for each impacted release: V11.5.9, V12.1.4 and V12.1.5. They can be applied to any affected level of the appropriate release to remediate this vulnerability.\n\n\n\n\n\nReleaseFixed in mod packAPARDownload URLV11.5TBD https://www.ibm.com/support/pages/node/7087189 \n\n\n\nV12.1\n\n\n\nTBD\n\n\n\n https://www.ibm.com/support/pages/node/7267513 \n\n\n\nSecurity Update #88454 or later for V12.1.5 available at this link:\n https://www.ibm.com/support/pages/node/7282633 \n\n\n\n\n\n\n\n\n\n\nIBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability."
        }
      ],
      "title": "IBM\u00ae Db2\u00ae federated server could allow a local attacker to obtain sensitive information due to the logging of plain text passwords in trace files."
    }
  },
  "cveMetadata": {
    "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
    "assignerShortName": "ibm",
    "cveId": "CVE-2026-18097",
    "datePublished": "2026-08-12T20:48:29.761Z",
    "dateReserved": "2026-07-28T17:15:50.150Z",
    "dateUpdated": "2026-08-14T22:14:38.325Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-18096 (GCVE-0-2026-18096)
Vulnerability from cvelistv5
Published
2026-08-12 20:47
Modified
2026-08-13 14:08
CWE
  • CWE-770 - Allocation of Resources Without Limits or Throttling
Summary
IBM Db2 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to cause a denial of service due to a memory leak.
References
Impacted products
Vendor Product Version
IBM Db2 Version: 12.1.5
    cpe:2.3:a:ibm:db2:12.1.5:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-18096",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-08-13T14:08:08.583733Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-08-13T14:08:28.076Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:ibm:db2:12.1.5:*:*:*:*:*:*:*"
          ],
          "product": "Db2",
          "vendor": "IBM",
          "versions": [
            {
              "status": "affected",
              "version": "12.1.5"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eIBM Db2 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to cause a denial of service due to a memory leak.\u003c/p\u003e"
            }
          ],
          "value": "IBM Db2 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to cause a denial of service due to a memory leak."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "LOW",
            "baseScore": 3.3,
            "baseSeverity": "LOW",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-770",
              "description": "CWE-770 Allocation of Resources Without Limits or Throttling",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-12T20:47:06.726Z",
        "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "shortName": "ibm"
      },
      "references": [
        {
          "tags": [
            "vendor-advisory",
            "patch"
          ],
          "url": "https://www.ibm.com/support/pages/node/7282953"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eCustomers running any vulnerable affected level of an affected Program, V12.1, can download the security update containing the interim fix for this issue from Fix Central. These security updates are available based on the most recent level for each impacted release: V12.1.5. They can be applied to any affected level of the appropriate release to remediate this vulnerability.\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\u003cstrong\u003eRelease\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eFixed in mod pack\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eAPAR\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eDownload URL\u003c/strong\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003e\u003cp\u003eV12.1\u00a0\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eTBD\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/defect/aCIgJ000000Fr2P/dt475495\" rel=\"nofollow\"\u003eDT475495\u003c/a\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eSecurity Update #88454 or later for V12.1.5 available at this link:\u003c/p\u003e\u003cpre\u003e\u003ca href=\"https://www.ibm.com/support/pages/node/7282633\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/pages/node/7282633\u003c/a\u003e\u003c/pre\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003cp\u003e\u003c/p\u003e\u003cp\u003eIBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability.\u003c/p\u003e"
            }
          ],
          "value": "Customers running any vulnerable affected level of an affected Program, V12.1, can download the security update containing the interim fix for this issue from Fix Central. These security updates are available based on the most recent level for each impacted release: V12.1.5. They can be applied to any affected level of the appropriate release to remediate this vulnerability.\n\n\n\n\n\nReleaseFixed in mod packAPARDownload URL\n\nV12.1\u00a0\n\n\n\nTBD\n\n\n\n https://www.ibm.com/support/pages/node/7282633 \n\n\n\n\n\n\n\n\n\nIBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability."
        }
      ],
      "title": "IBM\u00ae Db2\u00ae could allow a local attacker to cause a denial of service due to a memory leak"
    }
  },
  "cveMetadata": {
    "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
    "assignerShortName": "ibm",
    "cveId": "CVE-2026-18096",
    "datePublished": "2026-08-12T20:47:06.726Z",
    "dateReserved": "2026-07-28T17:11:56.662Z",
    "dateUpdated": "2026-08-13T14:08:28.076Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-10535 (GCVE-0-2026-10535)
Vulnerability from cvelistv5
Published
2026-07-30 16:55
Modified
2026-07-31 03:56
CWE
  • CWE-121 - Stack-based Buffer Overflow
Summary
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid helper db2flacc.
References
Impacted products
Vendor Product Version
IBM Db2 Version: 11.5.0    11.5.9
Version: 12.1.0    12.1.4
    cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:12.1.4:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-10535",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-07-30T00:00:00+00:00",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-07-31T03:56:17.992Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:12.1.4:*:*:*:*:*:*:*"
          ],
          "product": "Db2",
          "vendor": "IBM",
          "versions": [
            {
              "lessThanOrEqual": "11.5.9",
              "status": "affected",
              "version": "11.5.0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "12.1.4",
              "status": "affected",
              "version": "12.1.0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eIBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid helper db2flacc.\u003c/p\u003e"
            }
          ],
          "value": "IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid helper db2flacc."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 8.4,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-121",
              "description": "CWE-121 Stack-based Buffer Overflow",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-07-30T16:55:57.003Z",
        "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "shortName": "ibm"
      },
      "references": [
        {
          "tags": [
            "vendor-advisory",
            "patch"
          ],
          "url": "https://www.ibm.com/support/pages/node/7279466"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eCustomers running any vulnerable modpack level of an affected Program, V11.5, and V12.1, can download the special build containing the interim fix for this issue from Fix Central. These special builds are available based on the most recent level for each impacted release: V11.5.9, and V12.1.4. They can be applied to any affected level of the appropriate release to remediate this vulnerability.\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\u003cstrong\u003eRelease\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eFixed in mod pack\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eAPAR\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eDownload URL\u003c/strong\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eV11.5\u003c/td\u003e\u003ctd\u003eTBD\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/defect/aCIgJ000000ECJ3/dt471717\" rel=\"nofollow\"\u003eDT471717\u003c/a\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eSpecial Build #87098 or later for V11.5.9 available at this link:\u003cbr/\u003e\u003ca href=\"https://www.ibm.com/support/pages/node/7087189\" rel=\"noopener noreferrer nofollow\"\u003ehttps://www.ibm.com/support/pages/node/7087189\u003c/a\u003e\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eV12.1\u003c/td\u003e\u003ctd\u003ev12.1.5\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/defect/aCIgJ000000ECJ3/dt471717\" rel=\"nofollow\"\u003eDT471717\u003c/a\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eSpecial Build #87349 or later for V12.1.4 available at this link: \u003ca href=\"https://www.ibm.com/support/pages/node/7267513\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/pages/node/7267513\u003c/a\u003e\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003cp\u003e\u003c/p\u003e\u003cp\u003eIBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability.\u003c/p\u003e"
            }
          ],
          "value": "Customers running any vulnerable modpack level of an affected Program, V11.5, and V12.1, can download the special build containing the interim fix for this issue from Fix Central. These special builds are available based on the most recent level for each impacted release: V11.5.9, and V12.1.4. They can be applied to any affected level of the appropriate release to remediate this vulnerability.\n\n\n\n\n\nReleaseFixed in mod packAPARDownload URLV11.5TBD https://www.ibm.com/support/pages/node/7087189 \n\nV12.1v12.1.5 https://www.ibm.com/support/pages/node/7267513 \n\n\n\n\n\n\n\n\n\nIBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability."
        }
      ],
      "title": "IBM\u00ae Db2\u00ae is vulnerable to buffer overflow in setgid helper db2flacc which can lead to privilege escalation and instance compromise from an unprivileged shell"
    }
  },
  "cveMetadata": {
    "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
    "assignerShortName": "ibm",
    "cveId": "CVE-2026-10535",
    "datePublished": "2026-07-30T16:55:57.003Z",
    "dateReserved": "2026-06-01T11:45:31.382Z",
    "dateUpdated": "2026-07-31T03:56:17.992Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-10695 (GCVE-0-2026-10695)
Vulnerability from cvelistv5
Published
2026-07-30 16:55
Modified
2026-07-30 18:07
CWE
  • CWE-400 - Uncontrolled Resource Consumption
Summary
IBM Db2 12.1.0 through 12.1.4 federated server is vulnerable to a denial of service when running non fenced federated queries.
References
Impacted products
Vendor Product Version
IBM Db2 Version: 12.1.0    12.1.4
    cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:12.1.4:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-10695",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-07-30T18:04:09.746096Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-07-30T18:07:42.667Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:12.1.4:*:*:*:*:*:*:*"
          ],
          "product": "Db2",
          "vendor": "IBM",
          "versions": [
            {
              "lessThanOrEqual": "12.1.4",
              "status": "affected",
              "version": "12.1.0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eIBM Db2 12.1.0 through 12.1.4 federated server is vulnerable to a denial of service when running non fenced federated queries.\u003c/p\u003e"
            }
          ],
          "value": "IBM Db2 12.1.0 through 12.1.4 federated server is vulnerable to a denial of service when running non fenced federated queries."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 6.2,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-400",
              "description": "CWE-400 Uncontrolled Resource Consumption",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-07-30T16:55:20.162Z",
        "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "shortName": "ibm"
      },
      "references": [
        {
          "tags": [
            "vendor-advisory",
            "patch"
          ],
          "url": "https://www.ibm.com/support/pages/node/7279474"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eCustomers running any vulnerable modpack level of an affected Program, V12.1, can download the special build containing the interim fix for this issue from Fix Central. These special builds are available based on the most recent level for each impacted release: V12.1.4. They can be applied to any affected level of the appropriate release to remediate this vulnerability.\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\u003cstrong\u003eRelease\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eFixed in mod pack\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eAPAR\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eDownload URL\u003c/strong\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003e\u003cp\u003eV12.1\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003ev12.1.5\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/defect/aCIgJ000000BtcH/dt466396\" rel=\"nofollow\"\u003eDT466396\u003c/a\u003e\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eSpecial Build #87349 or later for V12.1.4 available at this link:\u00a0\u003ca href=\"https://www.ibm.com/support/pages/node/7267513\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/pages/node/7267513\u003c/a\u003e\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003cp\u003e\u003c/p\u003e\u003cp\u003eIBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability.\u003c/p\u003e"
            }
          ],
          "value": "Customers running any vulnerable modpack level of an affected Program, V12.1, can download the special build containing the interim fix for this issue from Fix Central. These special builds are available based on the most recent level for each impacted release: V12.1.4. They can be applied to any affected level of the appropriate release to remediate this vulnerability.\n\n\n\n\n\nReleaseFixed in mod packAPARDownload URL\n\nV12.1\n\n\n\n\n\n\n\nv12.1.5\n\n\n\n\n\n\n\n https://www.ibm.com/support/pages/node/7267513 \n\n\n\n\n\n\n\n\n\nIBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability."
        }
      ],
      "title": "IBM\u00ae Db2\u00ae is vulnerable to a denial of service when running non fenced federated queries",
      "workarounds": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eSet the federated wrapper to fenced mode using ALTER WRAPPER \u0026lt;wrapper_name\u0026gt; OPTIONS (SET DB2_FENCED \u0027Y\u0027)\u003c/p\u003e"
            }
          ],
          "value": "Set the federated wrapper to fenced mode using ALTER WRAPPER \u003cwrapper_name\u003e OPTIONS (SET DB2_FENCED \u0027Y\u0027)"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
    "assignerShortName": "ibm",
    "cveId": "CVE-2026-10695",
    "datePublished": "2026-07-30T16:55:20.162Z",
    "dateReserved": "2026-06-02T16:01:12.558Z",
    "dateUpdated": "2026-07-30T18:07:42.667Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-7771 (GCVE-0-2026-7771)
Vulnerability from cvelistv5
Published
2026-07-17 19:16
Modified
2026-07-21 02:03
CWE
  • CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')
Summary
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a trap when compiling a specially crafted statements containing subqueries could lead to a denial of service.
References
Impacted products
Vendor Product Version
IBM Db2 Version: 11.5.0    11.5.9
Version: 12.1.0    12.1.4
    cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:12.1.4:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-7771",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-07-21T02:02:58.525114Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-07-21T02:03:08.521Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:12.1.4:*:*:*:*:*:*:*"
          ],
          "product": "Db2",
          "vendor": "IBM",
          "versions": [
            {
              "lessThanOrEqual": "11.5.9",
              "status": "affected",
              "version": "11.5.0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "12.1.4",
              "status": "affected",
              "version": "12.1.0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eIBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a trap when compiling a specially crafted statements containing subqueries could lead to a denial of service.\u003c/p\u003e"
            }
          ],
          "value": "IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a trap when compiling a specially crafted statements containing subqueries could lead to a denial of service."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-835",
              "description": "CWE-835 Loop with Unreachable Exit Condition (\u0027Infinite Loop\u0027)",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-07-17T19:16:03.169Z",
        "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "shortName": "ibm"
      },
      "references": [
        {
          "tags": [
            "vendor-advisory",
            "patch"
          ],
          "url": "https://www.ibm.com/support/pages/node/7279480"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003e\u003cbr/\u003eCustomers running any vulnerable modpack level of an affected Program,V11.5, and V12.1, can download the special build containing the interim fix for this issue from Fix Central. These special builds are available based on the most recent level for each impacted release: V11.5.9, and V12.1.4. They can be applied to any affected level of the appropriate release to remediate this vulnerability.\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003eRelease\u003c/td\u003e\u003ctd\u003eFixed in mod pack\u003c/td\u003e\u003ctd\u003eAPAR\u003c/td\u003e\u003ctd\u003eDownload URL\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003e\u003cp\u003eV11.5\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eTBD\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/defect/aCIgJ000000DDib/dt469374\" rel=\"nofollow\"\u003eDT469374\u003c/a\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eSpecial Build #87098 or later for V11.5.9 available at this link:\u003cbr/\u003e\u003ca href=\"https://www.ibm.com/support/pages/node/7087189\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/pages/node/7087189\u003c/a\u003e\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003e\u003cp\u003eV12.1\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003e12.1.5\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/defect/aCIgJ000000DDib/dt469374\" rel=\"nofollow\"\u003eDT469374\u003c/a\u003e\u003cbr/\u003e\u003cp\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003eSpecial Build #87349 or later for V12.1.4 available at this link:\u003cbr/\u003e\u003ca href=\"https://www.ibm.com/support/pages/node/7267513\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/pages/node/7267513\u003c/a\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003cp\u003eIBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability.\u003c/p\u003e"
            }
          ],
          "value": "Customers running any vulnerable modpack level of an affected Program,V11.5, and V12.1, can download the special build containing the interim fix for this issue from Fix Central. These special builds are available based on the most recent level for each impacted release: V11.5.9, and V12.1.4. They can be applied to any affected level of the appropriate release to remediate this vulnerability.\n\n\n\n\n\nReleaseFixed in mod packAPARDownload URL\n\nV11.5\n\n\n\nTBD\n\n\n\n https://www.ibm.com/support/pages/node/7087189 \n\n\n\nV12.1\n\n\n\n\n\n\n\n12.1.5\n\n\n\n\n\n https://www.ibm.com/support/pages/node/7267513 \n\n\n\nIBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability."
        }
      ],
      "title": "IBM\u00ae Db2\u00ae is vulnerable to a trap when compiling specially crafted statements containing subqueries could lead to a denial of service",
      "workarounds": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eEnsure that the query is applying the predicates as intended.\u003c/p\u003e"
            }
          ],
          "value": "Ensure that the query is applying the predicates as intended."
        }
      ],
      "x_generator": {
        "engine": "ibm-cvegen"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
    "assignerShortName": "ibm",
    "cveId": "CVE-2026-7771",
    "datePublished": "2026-07-17T19:16:03.169Z",
    "dateReserved": "2026-05-04T14:17:26.954Z",
    "dateUpdated": "2026-07-21T02:03:08.521Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-9762 (GCVE-0-2026-9762)
Vulnerability from cvelistv5
Published
2026-07-17 17:25
Modified
2026-07-18 03:55
CWE
  • CWE-94 - Improper Control of Generation of Code ('Code Injection')
Summary
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when jdbc url is under user control.
References
Impacted products
Vendor Product Version
IBM Db2 Version: 11.5.0    11.5.9
Version: 12.1.0    12.1.4
    cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:12.1.4:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-9762",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-07-17T00:00:00+00:00",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-07-18T03:55:38.232Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:12.1.4:*:*:*:*:*:*:*"
          ],
          "product": "Db2",
          "vendor": "IBM",
          "versions": [
            {
              "lessThanOrEqual": "11.5.9",
              "status": "affected",
              "version": "11.5.0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "12.1.4",
              "status": "affected",
              "version": "12.1.0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eIBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when jdbc url is under user control.\u003c/p\u003e"
            }
          ],
          "value": "IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when jdbc url is under user control."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-94",
              "description": "CWE-94 Improper Control of Generation of Code (\u0027Code Injection\u0027)",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-07-17T17:25:53.469Z",
        "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "shortName": "ibm"
      },
      "references": [
        {
          "tags": [
            "vendor-advisory",
            "patch"
          ],
          "url": "https://www.ibm.com/support/pages/node/7279479"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eCustomers running any vulnerable modpack level of an affected Program, V11.5, V12.1, can download the special build containing the interim fix for this issue from Fix Central. These special builds are available based on the most recent level for each impacted release: V11.5.9 and V12.1.4. They can be applied to any affected level of the appropriate release to remediate this vulnerability.\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\u003cstrong\u003eRelease\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eFixed in mod pack\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eAPAR\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eDownload URL\u003c/strong\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003e\u003cp\u003eV11.5\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eTBD\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/defect/aCIgJ000000E5e9/dt471454\" rel=\"nofollow\"\u003eDT471454\u003c/a\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eSpecial Build #87098 or later for V11.5.9 available at this link:\u003cbr/\u003e\u003ca href=\"https://www.ibm.com/support/pages/node/7087189\" rel=\"noopener noreferrer nofollow\"\u003ehttps://www.ibm.com/support/pages/node/7087189\u003c/a\u003e\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003e\u003cp\u003eV12.1\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003ev12.1.5\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/defect/aCIgJ000000E5e9/dt471454\" rel=\"nofollow\"\u003eDT471454\u003c/a\u003e\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eSpecial Build #87349 or later for V12.1.4 available at this link:\u003c/p\u003e\u003cp\u003e\u003ca href=\"https://www.ibm.com/support/pages/node/7267513\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/pages/node/7267513\u003c/a\u003e\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003cp\u003e\u003c/p\u003e\u003cp\u003eIBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability.\u003c/p\u003e"
            }
          ],
          "value": "Customers running any vulnerable modpack level of an affected Program, V11.5, V12.1, can download the special build containing the interim fix for this issue from Fix Central. These special builds are available based on the most recent level for each impacted release: V11.5.9 and V12.1.4. They can be applied to any affected level of the appropriate release to remediate this vulnerability.ReleaseFixed in mod packAPARDownload URLV11.5TBDDT471454Special Build #87098 or later for V11.5.9 available at this link:https://www.ibm.com/support/pages/node/7087189V12.1v12.1.5DT471454Special Build #87349 or later for V12.1.4 available at this link:https://www.ibm.com/support/pages/node/7267513IBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability."
        }
      ],
      "title": "IBM\u00ae Data Server driver for JDBC and SQLJ is vulnerable to remote code execution when jdbc url is under user control",
      "x_generator": {
        "engine": "ibm-cvegen"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
    "assignerShortName": "ibm",
    "cveId": "CVE-2026-9762",
    "datePublished": "2026-07-17T17:25:53.469Z",
    "dateReserved": "2026-05-27T18:39:32.605Z",
    "dateUpdated": "2026-07-18T03:55:38.232Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2025-36372 (GCVE-0-2025-36372)
Vulnerability from cvelistv5
Published
2026-06-30 20:03
Modified
2026-07-01 14:29
CWE
  • CWE-538 - Insertion of Sensitive Information into Externally-Accessible File or Directory
Summary
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could disclose sensitive information to an authenticated user from the monitoring and event tables.
References
Impacted products
Vendor Product Version
IBM Db2 Version: 11.5.0    11.5.9
Version: 12.1.0    12.1.4
    cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:12.1.4:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2025-36372",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-07-01T13:49:30.901347Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-07-01T14:29:38.494Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:12.1.4:*:*:*:*:*:*:*"
          ],
          "product": "Db2",
          "vendor": "IBM",
          "versions": [
            {
              "lessThanOrEqual": "11.5.9",
              "status": "affected",
              "version": "11.5.0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "12.1.4",
              "status": "affected",
              "version": "12.1.0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eIBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could disclose sensitive information to an authenticated user from the monitoring and event tables.\u003c/p\u003e"
            }
          ],
          "value": "IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could disclose sensitive information to an authenticated user from the monitoring and event tables."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "NONE",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-538",
              "description": "CWE-538 Insertion of Sensitive Information into Externally-Accessible File or Directory",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-06-30T20:03:00.050Z",
        "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "shortName": "ibm"
      },
      "references": [
        {
          "tags": [
            "vendor-advisory",
            "patch"
          ],
          "url": "https://www.ibm.com/support/pages/node/7277417"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eCustomers running any vulnerable affected level of an affected Program, V11.5, and V12.1, can download the special build containing the interim fix for this issue from Fix Central. These special builds are available based on the most recent level for each impacted release: V11.5.9, and V12.1.4. They can be applied to any affected level of the appropriate release to remediate this vulnerability.\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\u003cstrong\u003eRelease\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eFixed in mod pack\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eAPAR\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eDownload URL\u003c/strong\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eV11.5\u003c/td\u003e\u003ctd\u003eTBD\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/defect/aCIgJ00000064Tx/dt452582\" rel=\"nofollow\"\u003eDT452582\u003c/a\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eSpecial Build #84653 or later for V11.5.9 available at this link:\u003cbr/\u003e\u003ca href=\"https://www.ibm.com/support/pages/node/7087189\" rel=\"noopener noreferrer nofollow\"\u003ehttps://www.ibm.com/support/pages/node/7087189\u003c/a\u003e\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003e\u003cp\u003eV12.1\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eTBD\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/defect/aCIgJ00000064Tx/dt452582\" rel=\"nofollow\"\u003eDT452582\u003c/a\u003e\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eSpecial Build #86230 or later for V12.1.4 available at this link:\u003cbr/\u003e\u003ca href=\"https://www.ibm.com/support/pages/node/7267513\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/pages/node/7267513\u003c/a\u003e\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003cp\u003e\u003c/p\u003e\u003cp\u003eIBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability.\u003c/p\u003e"
            }
          ],
          "value": "Customers running any vulnerable affected level of an affected Program, V11.5, and V12.1, can download the special build containing the interim fix for this issue from Fix Central. These special builds are available based on the most recent level for each impacted release: V11.5.9, and V12.1.4. They can be applied to any affected level of the appropriate release to remediate this vulnerability.\n\n\n\n\n\nReleaseFixed in mod packAPARDownload URLV11.5TBD https://www.ibm.com/support/pages/node/7087189 \n\n\n\nV12.1\n\n\n\n\n\n\n\nTBD\n\n\n\n\n\n\n\n https://www.ibm.com/support/pages/node/7267513 \n\n\n\n\n\n\n\n\n\nIBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability."
        }
      ],
      "title": "IBM\u00ae Db2\u00ae could disclose sensitive information to an authenticated user from the monitoring and event tables",
      "workarounds": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eUse DB2REMOTE alias. (DB2REMOTE is supported with LBAR only on 12.1 releases)\u003c/p\u003e"
            }
          ],
          "value": "Use DB2REMOTE alias. (DB2REMOTE is supported with LBAR only on 12.1 releases)"
        }
      ],
      "x_generator": {
        "engine": "ibm-cvegen"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
    "assignerShortName": "ibm",
    "cveId": "CVE-2025-36372",
    "datePublished": "2026-06-30T20:03:00.050Z",
    "dateReserved": "2025-04-15T21:16:56.325Z",
    "dateUpdated": "2026-07-01T14:29:38.494Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-10109 (GCVE-0-2026-10109)
Vulnerability from cvelistv5
Published
2026-06-30 20:02
Modified
2026-07-01 17:27
Severity ?
CWE
  • CWE-94 - Improper Control of Generation of Code ('Code Injection')
Summary
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution due to improper pre-auth DRDA handshake handling.
References
Impacted products
Vendor Product Version
IBM Db2 Version: 11.5.0    11.5.9
Version: 12.1.0    12.1.4
    cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:12.1.4:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-10109",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-07-01T03:56:04.853789Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-07-01T17:27:00.915Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:12.1.4:*:*:*:*:*:*:*"
          ],
          "product": "Db2",
          "vendor": "IBM",
          "versions": [
            {
              "lessThanOrEqual": "11.5.9",
              "status": "affected",
              "version": "11.5.0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "12.1.4",
              "status": "affected",
              "version": "12.1.0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eIBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution due to improper pre-auth DRDA handshake handling.\u003c/p\u003e"
            }
          ],
          "value": "IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution due to improper pre-auth DRDA handshake handling."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-94",
              "description": "CWE-94 Improper Control of Generation of Code (\u0027Code Injection\u0027)",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-06-30T20:02:13.026Z",
        "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "shortName": "ibm"
      },
      "references": [
        {
          "tags": [
            "vendor-advisory",
            "patch"
          ],
          "url": "https://www.ibm.com/support/pages/node/7277424"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eCustomers running any vulnerable affected level of an affected Program, V11.5, and V12.1, can download the special build containing the interim fix for this issue from Fix Central. These special builds are available based on the most recent level for each impacted release:V11.5.9, and V12.1.4. They can be applied to any affected level of the appropriate release to remediate this vulnerability.\u003c/p\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\u003cstrong\u003eRelease\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eFixed in mod pack\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eAPAR\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eDownload URL\u003c/strong\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eV11.5\u003c/td\u003e\u003ctd\u003eTBD\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/defect/aCIgJ000000ECKf/dt471718\" rel=\"nofollow\"\u003eDT471718\u003c/a\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eSpecial Build #84653 or later for V11.5.9 available at this link:\u003cbr/\u003e\u003ca href=\"https://www.ibm.com/support/pages/node/7087189\" rel=\"noopener noreferrer nofollow\"\u003ehttps://www.ibm.com/support/pages/node/7087189\u003c/a\u003e\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003e\u003cp\u003eV12.1\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eTBD\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/defect/aCIgJ000000ECKf/dt471718\" rel=\"nofollow\"\u003eDT471718\u003c/a\u003e\u003cbr/\u003e\u003cp\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eSpecial Build #86230 or later for V12.1.4 available at this link:\u003cbr/\u003e\u003ca href=\"https://www.ibm.com/support/pages/node/7267513\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/pages/node/7267513\u003c/a\u003e\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003cp\u003eIBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability.\u003c/p\u003e"
            }
          ],
          "value": "Customers running any vulnerable affected level of an affected Program, V11.5, and V12.1, can download the special build containing the interim fix for this issue from Fix Central. These special builds are available based on the most recent level for each impacted release:V11.5.9, and V12.1.4. They can be applied to any affected level of the appropriate release to remediate this vulnerability.\n\nReleaseFixed in mod packAPARDownload URLV11.5TBD https://www.ibm.com/support/pages/node/7087189 \n\n\n\nV12.1\n\n\n\n\n\n\n\nTBD\n\n\n\n\n\n https://www.ibm.com/support/pages/node/7267513 \n\n\n\n\n\nIBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability."
        }
      ],
      "title": "IBM\u00ae Db2\u00ae is vulnerable to remote code execution due to improper pre-auth DRDA handshake handling",
      "x_generator": {
        "engine": "ibm-cvegen"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
    "assignerShortName": "ibm",
    "cveId": "CVE-2026-10109",
    "datePublished": "2026-06-30T20:02:13.026Z",
    "dateReserved": "2026-05-29T16:58:35.341Z",
    "dateUpdated": "2026-07-01T17:27:00.915Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-11906 (GCVE-0-2026-11906)
Vulnerability from cvelistv5
Published
2026-06-30 19:42
Modified
2026-07-01 15:53
CWE
  • CWE-1284 - Improper Validation of Specified Quantity in Input
Summary
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in the data query logic of XMLTable-derived columns.
References
Impacted products
Vendor Product Version
IBM Db2 Version: 11.5.0    11.5.9
Version: 12.1.0    12.1.4
    cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:12.1.4:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-11906",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-07-01T15:53:15.458939Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-07-01T15:53:31.824Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:12.1.4:*:*:*:*:*:*:*"
          ],
          "product": "Db2",
          "vendor": "IBM",
          "versions": [
            {
              "lessThanOrEqual": "11.5.9",
              "status": "affected",
              "version": "11.5.0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "12.1.4",
              "status": "affected",
              "version": "12.1.0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eIBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an\u0026nbsp;authenticated user to cause a denial of service due to improper neutralization of special\u0026nbsp;elements in the data query logic of XMLTable-derived columns.\u003c/p\u003e"
            }
          ],
          "value": "IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an\u00a0authenticated user to cause a denial of service due to improper neutralization of special\u00a0elements in the data query logic of XMLTable-derived columns."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-1284",
              "description": "CWE-1284 Improper Validation of Specified Quantity in Input",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-06-30T19:42:08.459Z",
        "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "shortName": "ibm"
      },
      "references": [
        {
          "tags": [
            "vendor-advisory",
            "patch"
          ],
          "url": "https://www.ibm.com/support/pages/node/7277423"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eCustomers running any vulnerable affected level of an affected Program, V11.5, and V12.1, can download the special build containing the interim fix for this issue from Fix Central. These special builds are available based on the most recent level for each impacted release:V11.5.9, and V12.1.4. They can be applied to any affected level of the appropriate release to remediate this vulnerability.\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\u003cstrong\u003eRelease\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eFixed in mod pack\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eAPAR\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eDownload URL\u003c/strong\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eV11.5\u003c/td\u003e\u003ctd\u003eTBD\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/defect/aCIgJ000000BsUv/dt466352\" rel=\"nofollow\"\u003eDT466352\u003c/a\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eSpecial Build #84653 or later for V11.5.9 available at this link:\u003cbr/\u003e\u003ca href=\"https://www.ibm.com/support/pages/node/7087189\" rel=\"noopener noreferrer nofollow\"\u003ehttps://www.ibm.com/support/pages/node/7087189\u003c/a\u003e\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003e\u003cp\u003eV12.1\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eTBD\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/defect/aCIgJ000000BsUv/dt466352\" rel=\"nofollow\"\u003eDT466352\u003c/a\u003e\u003cbr/\u003e\u003cp\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eSpecial Build #86230 or later for V12.1.4 available at this link:\u003cbr/\u003e\u003ca href=\"https://www.ibm.com/support/pages/node/7267513\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/pages/node/7267513\u003c/a\u003e\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003cp\u003eIBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability.\u003c/p\u003e"
            }
          ],
          "value": "Customers running any vulnerable affected level of an affected Program, V11.5, and V12.1, can download the special build containing the interim fix for this issue from Fix Central. These special builds are available based on the most recent level for each impacted release:V11.5.9, and V12.1.4. They can be applied to any affected level of the appropriate release to remediate this vulnerability.\n\n\n\n\n\nReleaseFixed in mod packAPARDownload URLV11.5TBD https://www.ibm.com/support/pages/node/7087189 \n\n\n\nV12.1\n\n\n\n\n\n\n\nTBD\n\n\n\n\n\n https://www.ibm.com/support/pages/node/7267513 \n\n\n\n\n\nIBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability."
        }
      ],
      "title": "IBM\u00ae Db2\u00ae federated server is vulnerable to a denial of service due to improper neutralization of special elements in the data query logic of XMLTable-derived columns by autheticated user",
      "x_generator": {
        "engine": "ibm-cvegen"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
    "assignerShortName": "ibm",
    "cveId": "CVE-2026-11906",
    "datePublished": "2026-06-30T19:42:08.459Z",
    "dateReserved": "2026-06-10T16:11:41.935Z",
    "dateUpdated": "2026-07-01T15:53:31.824Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-6938 (GCVE-0-2026-6938)
Vulnerability from cvelistv5
Published
2026-05-27 13:11
Modified
2026-05-27 14:45
CWE
Summary
IBM Db2 12.1.0 through 12.1.4 is vulnerable to authorization bypass when uploading to a remote object storage path with a special query.
References
Impacted products
Vendor Product Version
IBM Db2 Version: 12.1.0    12.1.4
    cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:12.1.4:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-6938",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-05-27T14:45:23.148553Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-05-27T14:45:33.154Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:12.1.4:*:*:*:*:*:*:*"
          ],
          "product": "Db2",
          "vendor": "IBM",
          "versions": [
            {
              "lessThanOrEqual": "12.1.4",
              "status": "affected",
              "version": "12.1.0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eIBM Db2 12.1.0 through 12.1.4 is vulnerable to authorization bypass when uploading to a remote object storage path with a special query.\u003c/p\u003e"
            }
          ],
          "value": "IBM Db2 12.1.0 through 12.1.4 is vulnerable to authorization bypass when uploading to a remote object storage path with a special query."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-285",
              "description": "CWE-285 Improper Authorization",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-05-27T13:11:31.279Z",
        "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "shortName": "ibm"
      },
      "references": [
        {
          "tags": [
            "vendor-advisory",
            "patch"
          ],
          "url": "https://www.ibm.com/support/pages/node/7273559"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eCustomers running any vulnerable affected level of an affected Program, V12.1, can download the special build containing the interim fix for this issue from Fix Central. These special builds are available based on the most recent level for each impacted release: V12.1.4. They can be applied to any affected level of the appropriate release to remediate this vulnerability.\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\u003cstrong\u003eRelease\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eFixed in mod pack\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eAPAR\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eDownload URL\u003c/strong\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003e\u003cp\u003eV12.1\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eTBD\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/defect/aCIgJ000000CfaT/dt468154\" rel=\"nofollow\"\u003eDT468154\u003c/a\u003e\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eSpecial Build #83501 or later for V12.1.4 available at this link:\u003cbr\u003e\u003ca href=\"https://www.ibm.com/support/pages/node/7267513\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/pages/node/7267513\u003c/a\u003e\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003cp\u003e\u003c/p\u003e\u003cp\u003eIBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability.\u003c/p\u003e"
            }
          ],
          "value": "Customers running any vulnerable affected level of an affected Program, V12.1, can download the special build containing the interim fix for this issue from Fix Central. These special builds are available based on the most recent level for each impacted release: V12.1.4. They can be applied to any affected level of the appropriate release to remediate this vulnerability.\n\n\n\n\n\nReleaseFixed in mod packAPARDownload URL\n\nV12.1\n\n\n\n\n\n\n\nTBD\n\n\n\n\n\n\n\n https://www.ibm.com/support/pages/node/7267513 \n\n\n\n\n\n\n\n\n\nIBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability."
        }
      ],
      "title": "IBM\u00ae Db2\u00ae is vulnerable to authorization bypass when uploading to a remote object storage path with a special query",
      "workarounds": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eUse LOAD COPY command db2 load from test.del of del replace into t1 copy yes to \u0027DB2REMOTE://\u0027. Instead of the LOAD COPY via the regvar DB2_LOAD_COPY_NO_OVERRIDE\u003c/p\u003e"
            }
          ],
          "value": "Use LOAD COPY command db2 load from test.del of del replace into t1 copy yes to \u0027DB2REMOTE://\u0027. Instead of the LOAD COPY via the regvar DB2_LOAD_COPY_NO_OVERRIDE"
        }
      ],
      "x_generator": {
        "engine": "ibm-cvegen"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
    "assignerShortName": "ibm",
    "cveId": "CVE-2026-6938",
    "datePublished": "2026-05-27T13:11:31.279Z",
    "dateReserved": "2026-04-23T19:16:43.392Z",
    "dateUpdated": "2026-05-27T14:45:33.154Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-6053 (GCVE-0-2026-6053)
Vulnerability from cvelistv5
Published
2026-05-27 13:10
Modified
2026-05-29 15:32
CWE
  • CWE-770 - Allocation of Resources Without Limits or Throttling
Summary
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when a specially crafted query is run with range partitioned tables.
References
Impacted products
Vendor Product Version
IBM Db2 Version: 11.5.0    11.5.9
Version: 12.1.0    12.1.4
    cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:12.1.4:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-6053",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-05-29T15:32:03.289212Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-05-29T15:32:13.728Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:12.1.4:*:*:*:*:*:*:*"
          ],
          "product": "Db2",
          "vendor": "IBM",
          "versions": [
            {
              "lessThanOrEqual": "11.5.9",
              "status": "affected",
              "version": "11.5.0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "12.1.4",
              "status": "affected",
              "version": "12.1.0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eIBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when a specially crafted query is run with range partitioned tables.\u003c/p\u003e"
            }
          ],
          "value": "IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when a specially crafted query is run with range partitioned tables."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-770",
              "description": "CWE-770 Allocation of Resources Without Limits or Throttling",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-05-27T13:10:05.402Z",
        "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "shortName": "ibm"
      },
      "references": [
        {
          "tags": [
            "vendor-advisory",
            "patch"
          ],
          "url": "https://www.ibm.com/support/pages/node/7273556"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eCustomers running any vulnerable affected level of an affected Program, V11.5, and V12.1, can download the special build containing the interim fix for this issue from Fix Central. These special builds are available based on the most recent level for each impacted release: V11.5.9, and V12.1.4. They can be applied to any affected level of the appropriate release to remediate this vulnerability.\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\u003cstrong\u003eRelease\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eFixed in mod pack\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eAPAR\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eDownload URL\u003c/strong\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eV11.5\u003c/td\u003e\u003ctd\u003eTBD\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/defect/aCIgJ000000BUkL/dt465436\" rel=\"nofollow\"\u003eDT465436\u003c/a\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eSpecial Build #81937 or later for V11.5.9 available at this link:\u003cbr\u003e\u003ca href=\"https://www.ibm.com/support/pages/node/7087189\" rel=\"noopener noreferrer nofollow\"\u003ehttps://www.ibm.com/support/pages/node/7087189\u003c/a\u003e\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003e\u003cp\u003eV12.1\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eTBD\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/defect/aCIgJ000000BUkL/dt465436\" rel=\"nofollow\"\u003eDT465436\u003c/a\u003e\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eSpecial Build #83501 or later for V12.1.4 available at this link:\u003cbr\u003e\u003ca href=\"https://www.ibm.com/support/pages/node/7267513\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/pages/node/7267513\u003c/a\u003e\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003cp\u003e\u003c/p\u003e\u003cp\u003eIBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability.\u003c/p\u003e"
            }
          ],
          "value": "Customers running any vulnerable affected level of an affected Program, V11.5, and V12.1, can download the special build containing the interim fix for this issue from Fix Central. These special builds are available based on the most recent level for each impacted release: V11.5.9, and V12.1.4. They can be applied to any affected level of the appropriate release to remediate this vulnerability.\n\n\n\n\n\nReleaseFixed in mod packAPARDownload URLV11.5TBD https://www.ibm.com/support/pages/node/7087189 \n\n\n\nV12.1\n\n\n\n\n\n\n\nTBD\n\n\n\n\n\n\n\n https://www.ibm.com/support/pages/node/7267513 \n\n\n\n\n\n\n\n\n\nIBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability."
        }
      ],
      "title": "IBM\u00ae Db2\u00ae is vulnerable to a denial of service when a specially crafted query is run with range partitioned tables",
      "workarounds": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eTurn off intra-parallelism. Ensure sufficient memory available in the application heap to avoid memory allocation from failing.\u003c/p\u003e"
            }
          ],
          "value": "Turn off intra-parallelism. Ensure sufficient memory available in the application heap to avoid memory allocation from failing."
        }
      ],
      "x_generator": {
        "engine": "ibm-cvegen"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
    "assignerShortName": "ibm",
    "cveId": "CVE-2026-6053",
    "datePublished": "2026-05-27T13:10:05.402Z",
    "dateReserved": "2026-04-09T22:16:06.393Z",
    "dateUpdated": "2026-05-29T15:32:13.728Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-6052 (GCVE-0-2026-6052)
Vulnerability from cvelistv5
Published
2026-05-27 13:09
Modified
2026-05-27 15:22
Summary
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to running out of memory when executing certain queries with MDC tables.
References
Impacted products
Vendor Product Version
IBM Db2 Version: 11.5.0    11.5.9
Version: 12.1.0    12.1.4
    cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:12.1.4:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-6052",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-05-27T15:21:52.352065Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-400",
                "description": "CWE-400 Uncontrolled Resource Consumption",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-05-27T15:22:19.791Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:12.1.4:*:*:*:*:*:*:*"
          ],
          "product": "Db2",
          "vendor": "IBM",
          "versions": [
            {
              "lessThanOrEqual": "11.5.9",
              "status": "affected",
              "version": "11.5.0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "12.1.4",
              "status": "affected",
              "version": "12.1.0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eIBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to running out of memory when executing certain queries with MDC tables.\u003c/p\u003e"
            }
          ],
          "value": "IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to running out of memory when executing certain queries with MDC tables."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-05-27T13:09:29.770Z",
        "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "shortName": "ibm"
      },
      "references": [
        {
          "tags": [
            "vendor-advisory",
            "patch"
          ],
          "url": "https://www.ibm.com/support/pages/node/7273557"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eCustomers running any vulnerable affected level of an affected Program, V11.5, and V12.1, can download the special build containing the interim fix for this issue from Fix Central. These special builds are available based on the most recent level for each impacted release: V11.5.9, and V12.1.4. They can be applied to any affected level of the appropriate release to remediate this vulnerability.\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\u003cstrong\u003eRelease\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eFixed in mod pack\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eAPAR\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eDownload URL\u003c/strong\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eV11.5\u003c/td\u003e\u003ctd\u003eTBD\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/defect/aCIgJ000000BcEr/dt465726\" rel=\"nofollow\"\u003eDT465726\u003c/a\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eSpecial Build #81937 or later for V11.5.9 available at this link:\u003cbr\u003e\u003ca href=\"https://www.ibm.com/support/pages/node/7087189\" rel=\"noopener noreferrer nofollow\"\u003ehttps://www.ibm.com/support/pages/node/7087189\u003c/a\u003e\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003e\u003cp\u003eV12.1\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eTBD\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/defect/aCIgJ000000BcEr/dt465726\" rel=\"nofollow\"\u003eDT465726\u003c/a\u003e\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eSpecial Build #83501 or later for V12.1.4 available at this link:\u003cbr\u003e\u003ca href=\"https://www.ibm.com/support/pages/node/7267513\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/pages/node/7267513\u003c/a\u003e\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003cp\u003e\u003c/p\u003e\u003cp\u003eIBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability.\u003c/p\u003e"
            }
          ],
          "value": "Customers running any vulnerable affected level of an affected Program, V11.5, and V12.1, can download the special build containing the interim fix for this issue from Fix Central. These special builds are available based on the most recent level for each impacted release: V11.5.9, and V12.1.4. They can be applied to any affected level of the appropriate release to remediate this vulnerability.\n\n\n\n\n\nReleaseFixed in mod packAPARDownload URLV11.5TBD https://www.ibm.com/support/pages/node/7087189 \n\n\n\nV12.1\n\n\n\n\n\n\n\nTBD\n\n\n\n\n\n\n\n https://www.ibm.com/support/pages/node/7267513 \n\n\n\n\n\n\n\n\n\nIBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability."
        }
      ],
      "title": "IBM\u00ae Db2\u00ae is vulnerable to running out of memory when executing certain queries with MDC tables",
      "workarounds": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eDo not use Multi-Clustering-Dimensional (MDC) tables\u003c/p\u003e"
            }
          ],
          "value": "Do not use Multi-Clustering-Dimensional (MDC) tables"
        }
      ],
      "x_generator": {
        "engine": "ibm-cvegen"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
    "assignerShortName": "ibm",
    "cveId": "CVE-2026-6052",
    "datePublished": "2026-05-27T13:09:29.770Z",
    "dateReserved": "2026-04-09T22:08:53.174Z",
    "dateUpdated": "2026-05-27T15:22:19.791Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-6051 (GCVE-0-2026-6051)
Vulnerability from cvelistv5
Published
2026-05-27 13:07
Modified
2026-05-27 14:41
CWE
  • CWE-400 - Uncontrolled Resource Consumption
Summary
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when executing a specially crafted query with a small statement heap.
References
Impacted products
Vendor Product Version
IBM Db2 Version: 11.5.0    11.5.9
Version: 12.1.0    12.1.4
    cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:12.1.4:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-6051",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-05-27T14:38:57.077391Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-05-27T14:41:58.407Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:12.1.4:*:*:*:*:*:*:*"
          ],
          "product": "Db2",
          "vendor": "IBM",
          "versions": [
            {
              "lessThanOrEqual": "11.5.9",
              "status": "affected",
              "version": "11.5.0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "12.1.4",
              "status": "affected",
              "version": "12.1.0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eIBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when executing a specially crafted query with a small statement heap.\u003c/p\u003e"
            }
          ],
          "value": "IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when executing a specially crafted query with a small statement heap."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-400",
              "description": "CWE-400 Uncontrolled Resource Consumption",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-05-27T13:07:47.761Z",
        "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "shortName": "ibm"
      },
      "references": [
        {
          "tags": [
            "vendor-advisory",
            "patch"
          ],
          "url": "https://www.ibm.com/support/pages/node/7273558"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eCustomers running any vulnerable affected level of an affected Program, V11.5, and V12.1, can download the special build containing the interim fix for this issue from Fix Central. These special builds are available based on the most recent level for each impacted release: V11.5.9, and V12.1.4. They can be applied to any affected level of the appropriate release to remediate this vulnerability.\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\u003cstrong\u003eRelease\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eFixed in mod pack\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eAPAR\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eDownload URL\u003c/strong\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eV11.5\u003c/td\u003e\u003ctd\u003eTBD\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/defect/aCIgJ000000BxZR/dt466547\" rel=\"nofollow\"\u003eDT466547\u003c/a\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eSpecial Build #81937 or later for V11.5.9 available at this link:\u003cbr\u003e\u003ca href=\"https://www.ibm.com/support/pages/node/7087189\" rel=\"noopener noreferrer nofollow\"\u003ehttps://www.ibm.com/support/pages/node/7087189\u003c/a\u003e\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003e\u003cp\u003eV12.1\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eTBD\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/defect/aCIgJ000000BxZR/dt466547\" rel=\"nofollow\"\u003eDT466547\u003c/a\u003e\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eSpecial Build #83501 or later for V12.1.4 available at this link:\u003cbr\u003e\u003ca href=\"https://www.ibm.com/support/pages/node/7267513\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/pages/node/7267513\u003c/a\u003e\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003cp\u003e\u003c/p\u003e\u003cp\u003eIBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability.\u003c/p\u003e"
            }
          ],
          "value": "Customers running any vulnerable affected level of an affected Program, V11.5, and V12.1, can download the special build containing the interim fix for this issue from Fix Central. These special builds are available based on the most recent level for each impacted release: V11.5.9, and V12.1.4. They can be applied to any affected level of the appropriate release to remediate this vulnerability.\n\n\n\n\n\nReleaseFixed in mod packAPARDownload URLV11.5TBD https://www.ibm.com/support/pages/node/7087189 \n\n\n\nV12.1\n\n\n\n\n\n\n\nTBD\n\n\n\n\n\n\n\n https://www.ibm.com/support/pages/node/7267513 \n\n\n\n\n\n\n\n\n\nIBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability."
        }
      ],
      "title": "IBM\u00ae Db2\u00ae is vulnerable to a denial of service when executing a specially crafted query with a small statement heap",
      "workarounds": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003e1) Increase statement heap by setting larger STMTHEAP.\u003c/p\u003e\u003cp\u003eor\u003c/p\u003e\u003cp\u003e2) Reduce optimization level to 0. The user can append a optimizer guideline to the query:\u003c/p\u003e\u003cp\u003e\u0026lt;query\u0026gt;\u003c/p\u003e\u003cp\u003e/* \u0026lt;OPTGUIDELINES\u0026gt;\u003c/p\u003e\u003cp\u003e\u00a0\u00a0\u0026lt;QRYOPT VALUE=\u00270\u0027/\u0026gt;\u003c/p\u003e\u003cp\u003e\u0026lt;/OPTGUIDELINES\u0026gt; */\u003c/p\u003e"
            }
          ],
          "value": "1) Increase statement heap by setting larger STMTHEAP.\n\n\n\nor\n\n\n\n2) Reduce optimization level to 0. The user can append a optimizer guideline to the query:\n\n\n\n\u003cquery\u003e\n\n\n\n/* \u003cOPTGUIDELINES\u003e\n\n\n\n\u00a0\u00a0\u003cQRYOPT VALUE=\u00270\u0027/\u003e\n\n\n\n\u003c/OPTGUIDELINES\u003e */"
        }
      ],
      "x_generator": {
        "engine": "ibm-cvegen"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
    "assignerShortName": "ibm",
    "cveId": "CVE-2026-6051",
    "datePublished": "2026-05-27T13:07:47.761Z",
    "dateReserved": "2026-04-09T21:45:54.618Z",
    "dateUpdated": "2026-05-27T14:41:58.407Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-1718 (GCVE-0-2026-1718)
Vulnerability from cvelistv5
Published
2026-05-27 12:18
Modified
2026-05-27 15:00
CWE
  • CWE-770 - Allocation of Resources Without Limits or Throttling
Summary
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service with a specially crafted query when autonomous transactions are enabled.
References
Impacted products
Vendor Product Version
IBM Db2 Version: 11.5.0    11.5.9
Version: 12.1.0    12.1.4
    cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:12.1.4:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-1718",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-05-27T14:58:14.515036Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-05-27T15:00:16.607Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:12.1.4:*:*:*:*:*:*:*"
          ],
          "product": "Db2",
          "vendor": "IBM",
          "versions": [
            {
              "lessThanOrEqual": "11.5.9",
              "status": "affected",
              "version": "11.5.0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "12.1.4",
              "status": "affected",
              "version": "12.1.0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eIBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service with a specially crafted query when autonomous transactions are enabled.\u003c/p\u003e"
            }
          ],
          "value": "IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service with a specially crafted query when autonomous transactions are enabled."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-770",
              "description": "CWE-770 Allocation of Resources Without Limits or Throttling",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-05-27T12:18:40.738Z",
        "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "shortName": "ibm"
      },
      "references": [
        {
          "tags": [
            "vendor-advisory",
            "patch"
          ],
          "url": "https://www.ibm.com/support/pages/node/7273555"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eCustomers running any vulnerable affected level of an affected Program, V11.5, and V12.1, can download the special build containing the interim fix for this issue from Fix Central. These special builds are available based on the most recent level for each impacted release: V11.5.9, and V12.1.4. They can be applied to any affected level of the appropriate release to remediate this vulnerability.\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\u003cstrong\u003eRelease\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eFixed in mod pack\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eAPAR\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eDownload URL\u003c/strong\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eV11.5\u003c/td\u003e\u003ctd\u003eTBD\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/defect/aCIgJ00000093WX/dt459656\" rel=\"nofollow\"\u003eDT459656\u003c/a\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eSpecial Build #81937 or later for V11.5.9 available at this link:\u003cbr\u003e\u003ca href=\"https://www.ibm.com/support/pages/node/7087189\" rel=\"noopener noreferrer nofollow\"\u003ehttps://www.ibm.com/support/pages/node/7087189\u003c/a\u003e\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003e\u003cp\u003eV12.1\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eTBD\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/defect/aCIgJ00000093WX/dt459656\" rel=\"nofollow\"\u003eDT459656\u003c/a\u003e\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eSpecial Build #83501 or later for V12.1.4 available at this link:\u003cbr\u003e\u003ca href=\"https://www.ibm.com/support/pages/node/7267513\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/pages/node/7267513\u003c/a\u003e\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003cp\u003e\u003c/p\u003e\u003cp\u003eIBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability.\u003c/p\u003e"
            }
          ],
          "value": "Customers running any vulnerable affected level of an affected Program, V11.5, and V12.1, can download the special build containing the interim fix for this issue from Fix Central. These special builds are available based on the most recent level for each impacted release: V11.5.9, and V12.1.4. They can be applied to any affected level of the appropriate release to remediate this vulnerability.\n\n\n\n\n\nReleaseFixed in mod packAPARDownload URLV11.5TBD https://www.ibm.com/support/pages/node/7087189 \n\n\n\nV12.1\n\n\n\n\n\n\n\nTBD\n\n\n\n\n\n\n\n https://www.ibm.com/support/pages/node/7267513 \n\n\n\n\n\n\n\n\n\nIBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability."
        }
      ],
      "title": "IBM\u00ae Db2\u00ae is vulnerable to a denial of service with a specially crafted query when running an AUTONOMOUS procedure",
      "workarounds": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eremove AUTONOMOUS from procedure define\u003c/p\u003e"
            }
          ],
          "value": "remove AUTONOMOUS from procedure define"
        }
      ],
      "x_generator": {
        "engine": "ibm-cvegen"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
    "assignerShortName": "ibm",
    "cveId": "CVE-2026-1718",
    "datePublished": "2026-05-27T12:18:40.738Z",
    "dateReserved": "2026-01-30T19:11:27.471Z",
    "dateUpdated": "2026-05-27T15:00:16.607Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2025-13755 (GCVE-0-2025-13755)
Vulnerability from cvelistv5
Published
2026-05-26 15:46
Modified
2026-05-26 17:51
CWE
  • CWE-532 - Insertion of Sensitive Information into Log File
Summary
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes DB2 Connect Server) stores potentially sensitive information in log files that could be read by a local user.
References
Impacted products
Vendor Product Version
IBM Db2 Version: 11.5.0    11.5.9
Version: 12.1.0    12.1.4
    cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:12.1.4:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2025-13755",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-05-26T17:50:42.431138Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-05-26T17:51:09.240Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:12.1.4:*:*:*:*:*:*:*"
          ],
          "product": "Db2",
          "vendor": "IBM",
          "versions": [
            {
              "lessThanOrEqual": "11.5.9",
              "status": "affected",
              "version": "11.5.0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "12.1.4",
              "status": "affected",
              "version": "12.1.0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eIBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes DB2 Connect Server) stores potentially sensitive information in log files that could be read by a local user.\u003c/p\u003e"
            }
          ],
          "value": "IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes DB2 Connect Server) stores potentially sensitive information in log files that could be read by a local user."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "NONE",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-532",
              "description": "CWE-532 Insertion of Sensitive Information into Log File",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-05-26T15:46:55.171Z",
        "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "shortName": "ibm"
      },
      "references": [
        {
          "tags": [
            "vendor-advisory",
            "patch"
          ],
          "url": "https://www.ibm.com/support/pages/node/7273554"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eCustomers running any vulnerable affected level of an affected Program, V11.5, and V12.1, can download the special build containing the interim fix for this issue from Fix Central. These special builds are available based on the most recent level for each impacted release: V11.5.9, and V12.1.4. They can be applied to any affected level of the appropriate release to remediate this vulnerability.\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\u003cstrong\u003eRelease\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eFixed in mod pack\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eAPAR\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eDownload URL\u003c/strong\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eV11.5\u003c/td\u003e\u003ctd\u003eTBD\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/defect/aCIgJ0000006rhZ/dt454491\" rel=\"nofollow\"\u003eDT454491\u003c/a\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eSpecial Build #81937 or later for V11.5.9 available at this link:\u003cbr\u003e\u003ca href=\"https://www.ibm.com/support/pages/node/7087189\" rel=\"noopener noreferrer nofollow\"\u003ehttps://www.ibm.com/support/pages/node/7087189\u003c/a\u003e\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003e\u003cp\u003eV12.1\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eTBD\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/defect/aCIgJ0000006rhZ/dt454491\" rel=\"nofollow\"\u003eDT454491\u003c/a\u003e\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eSpecial Build #83501 or later for V12.1.4 available at this link:\u003cbr\u003e\u003ca href=\"https://www.ibm.com/support/pages/node/7267513\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/pages/node/7267513\u003c/a\u003e\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003cp\u003e\u003c/p\u003e\u003cp\u003eIBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability.\u003c/p\u003e"
            }
          ],
          "value": "Customers running any vulnerable affected level of an affected Program, V11.5, and V12.1, can download the special build containing the interim fix for this issue from Fix Central. These special builds are available based on the most recent level for each impacted release: V11.5.9, and V12.1.4. They can be applied to any affected level of the appropriate release to remediate this vulnerability.\n\n\n\n\n\nReleaseFixed in mod packAPARDownload URLV11.5TBD https://www.ibm.com/support/pages/node/7087189 \n\n\n\nV12.1\n\n\n\n\n\n\n\nTBD\n\n\n\n\n\n\n\n https://www.ibm.com/support/pages/node/7267513 \n\n\n\n\n\n\n\n\n\nIBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability."
        }
      ],
      "title": "IBM\u00ae Db2\u00ae is vulnerable to credential exposure in db2diag when executing specific testcase buckets",
      "workarounds": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eSet the diaglevel to 2, 1 or 0\u003c/p\u003e"
            }
          ],
          "value": "Set the diaglevel to 2, 1 or 0"
        }
      ],
      "x_generator": {
        "engine": "ibm-cvegen"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
    "assignerShortName": "ibm",
    "cveId": "CVE-2025-13755",
    "datePublished": "2026-05-26T15:46:55.171Z",
    "dateReserved": "2025-11-26T19:41:29.841Z",
    "dateUpdated": "2026-05-26T17:51:09.240Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-1577 (GCVE-0-2026-1577)
Vulnerability from cvelistv5
Published
2026-04-30 21:49
Modified
2026-05-10 13:21
Summary
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic.
References
Impacted products
Vendor Product Version
IBM Db2 Version: 11.5.0    11.5.9
Version: 12.1.0    12.1.4
    cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:12.1.4:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-1577",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-05-01T16:06:31.745842Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-20",
                "description": "CWE-20 Improper Input Validation",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-05-10T13:21:48.830Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:12.1.4:*:*:*:*:*:*:*"
          ],
          "product": "Db2",
          "vendor": "IBM",
          "versions": [
            {
              "lessThanOrEqual": "11.5.9",
              "status": "affected",
              "version": "11.5.0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "12.1.4",
              "status": "affected",
              "version": "12.1.0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eIBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an\u0026nbsp;authenticated user to cause a denial of service due to improper neutralization of special\u0026nbsp;elements in data query logic.\u003c/p\u003e"
            }
          ],
          "value": "IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an\u00a0authenticated user to cause a denial of service due to improper neutralization of special\u00a0elements in data query logic."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-04-30T21:49:24.614Z",
        "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "shortName": "ibm"
      },
      "references": [
        {
          "tags": [
            "vendor-advisory",
            "patch"
          ],
          "url": "https://www.ibm.com/support/pages/node/7269434"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eCustomers running any vulnerable affected level of an affected Program, V11.5, and V12.1, can download the special build containing the interim fix for this issue from Fix Central. These special builds are available based on the most recent level for each impacted release: V11.5.9, and V12.1.4. They can be applied to any affected level of the appropriate release to remediate this vulnerability.\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\u003cstrong\u003eRelease\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eFixed in mod pack\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eAPAR\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eDownload URL\u003c/strong\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eV11.5\u003c/td\u003e\u003ctd\u003eTBD\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/defect/aCIgJ0000009d3l/dt460939\" rel=\"nofollow\"\u003eDT460939\u003c/a\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eSpecial Build #79671 or later for V11.5.9 available at this link:\u003cbr\u003e\u003ca href=\"https://www.ibm.com/support/pages/node/7087189\" rel=\"noopener noreferrer nofollow\"\u003ehttps://www.ibm.com/support/pages/node/7087189\u003c/a\u003e\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003e\u003cp\u003eV12.1\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eTBD\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/defect/aCIgJ0000009d3l/dt460939\" rel=\"nofollow\"\u003eDT460939\u003c/a\u003e\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eSpecial Build #80714 or later for V12.1.4 available at this link:\u003cbr\u003e\u003ca href=\"https://www.ibm.com/support/pages/node/7267513\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/pages/node/7267513\u003c/a\u003e\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003cp\u003e\u003c/p\u003e\u003cp\u003eIBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability.\u003c/p\u003e"
            }
          ],
          "value": "Customers running any vulnerable affected level of an affected Program, V11.5, and V12.1, can download the special build containing the interim fix for this issue from Fix Central. These special builds are available based on the most recent level for each impacted release: V11.5.9, and V12.1.4. They can be applied to any affected level of the appropriate release to remediate this vulnerability.\n\n\n\n\n\nReleaseFixed in mod packAPARDownload URLV11.5TBD https://www.ibm.com/support/pages/node/7087189 \n\n\n\nV12.1\n\n\n\n\n\n\n\nTBD\n\n\n\n\n\n\n\n https://www.ibm.com/support/pages/node/7267513 \n\n\n\n\n\n\n\n\n\nIBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability."
        }
      ],
      "title": "IBM\u00ae Db2\u00ae is vulnerable to a denial of service with a specially crafted query involving multiple subqueries",
      "x_generator": {
        "engine": "ibm-cvegen"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
    "assignerShortName": "ibm",
    "cveId": "CVE-2026-1577",
    "datePublished": "2026-04-30T21:49:24.614Z",
    "dateReserved": "2026-01-28T21:49:07.049Z",
    "dateUpdated": "2026-05-10T13:21:48.830Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2025-36122 (GCVE-0-2025-36122)
Vulnerability from cvelistv5
Published
2026-04-30 21:48
Modified
2026-05-27 16:34
CWE
  • CWE-770 - Allocation of Resources Without Limits or Throttling
Summary
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of service using a specially crafted SQL query due to improper allocation of system resources.
References
Impacted products
Vendor Product Version
IBM Db2 Version: 11.5.0    11.5.9
Version: 12.1.0    12.1.3
    cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:12.1.3:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2025-36122",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-05-01T14:24:09.617346Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-05-27T16:34:17.558Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:12.1.3:*:*:*:*:*:*:*"
          ],
          "product": "Db2",
          "vendor": "IBM",
          "versions": [
            {
              "lessThanOrEqual": "11.5.9",
              "status": "affected",
              "version": "11.5.0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "12.1.3",
              "status": "affected",
              "version": "12.1.0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eIBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of service using a specially crafted SQL query due to improper allocation of system resources.\u003c/p\u003e"
            }
          ],
          "value": "IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of service using a specially crafted SQL query due to improper allocation of system resources."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-770",
              "description": "CWE-770 Allocation of Resources Without Limits or Throttling",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-04-30T21:48:49.826Z",
        "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "shortName": "ibm"
      },
      "references": [
        {
          "tags": [
            "vendor-advisory",
            "patch"
          ],
          "url": "https://www.ibm.com/support/pages/node/7267642"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eCustomers running any vulnerable affected level of an affected Program, V11.5, and V12.1, can download the special build containing the interim fix for this issue from Fix Central. These special builds are available based on the most recent level for each impacted release: V11.5.9. They can be applied to any affected level of the appropriate release to remediate this vulnerability.\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\u003cstrong\u003eRelease\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eFixed in mod pack\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eAPAR\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eDownload URL\u003c/strong\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eV11.5\u003c/td\u003e\u003ctd\u003eTBD\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/defect/aCIgJ0000002v3p/dt444599\" rel=\"nofollow\"\u003eDT444599\u003c/a\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eSpecial Build #79671 or later for V11.5.9 available at this link:\u003cbr\u003e\u003ca href=\"https://www.ibm.com/support/pages/node/7087189\" rel=\"noopener noreferrer nofollow\"\u003ehttps://www.ibm.com/support/pages/node/7087189\u003c/a\u003e\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003e\u003cp\u003eV12.1\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eV12.1.4\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/defect/aCIgJ0000002v3p/dt444599\" rel=\"nofollow\"\u003eDT444599\u003c/a\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eLatest for V12.1.4 is available at this link:\u003cbr\u003e\u003ca href=\"https://www.ibm.com/support/pages/node/7267513\" rel=\"noopener noreferrer nofollow\"\u003ehttps://www.ibm.com/support/pages/node/7267513\u003c/a\u003e\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003cpre\u003e\u003cbr\u003eNote: To apply this fix, it is required to set DB2_STRICT_INSTANCE_MEMORY=ON in addition to installing the above Special Build.\u003cbr\u003e\u003c/pre\u003e\u003cp\u003eIBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability.\u003c/p\u003e"
            }
          ],
          "value": "Customers running any vulnerable affected level of an affected Program, V11.5, and V12.1, can download the special build containing the interim fix for this issue from Fix Central. These special builds are available based on the most recent level for each impacted release: V11.5.9. They can be applied to any affected level of the appropriate release to remediate this vulnerability.\n\n\n\n\n\nReleaseFixed in mod packAPARDownload URLV11.5TBD https://www.ibm.com/support/pages/node/7087189 \n\n\n\nV12.1\n\n\n\nV12.1.4\n\n\n\n https://www.ibm.com/support/pages/node/7267513 \n\n\n\n\n\n\nNote: To apply this fix, it is required to set DB2_STRICT_INSTANCE_MEMORY=ON in addition to installing the above Special Build.\n\n\n\n\nIBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability."
        }
      ],
      "title": "IBM\u00ae Db2\u00ae is vulnerable to a denial of service with a specially crafted query when stmtheap is set to automatic",
      "workarounds": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eset dbm cfg instance_memory to a fixed value\u003c/p\u003e"
            }
          ],
          "value": "set dbm cfg instance_memory to a fixed value"
        }
      ],
      "x_generator": {
        "engine": "ibm-cvegen"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
    "assignerShortName": "ibm",
    "cveId": "CVE-2025-36122",
    "datePublished": "2026-04-30T21:48:49.826Z",
    "dateReserved": "2025-04-15T21:16:18.171Z",
    "dateUpdated": "2026-05-27T16:34:17.558Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2025-14688 (GCVE-0-2025-14688)
Vulnerability from cvelistv5
Published
2026-04-30 21:48
Modified
2026-05-27 16:33
CWE
  • CWE-1284 - Improper Validation of Specified Quantity in Input
Summary
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic when certain configurations exist.
References
Impacted products
Vendor Product Version
IBM Db2 Version: 11.5.0    11.5.9
Version: 12.1.0    12.1.3
    cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:*:*:*
    cpe:2.3:a:ibm:db2:12.1.3:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2025-14688",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-05-01T16:06:41.376633Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-05-27T16:33:29.099Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:db2:12.1.3:*:*:*:*:*:*:*"
          ],
          "product": "Db2",
          "vendor": "IBM",
          "versions": [
            {
              "lessThanOrEqual": "11.5.9",
              "status": "affected",
              "version": "11.5.0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "12.1.3",
              "status": "affected",
              "version": "12.1.0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eIBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic when certain configurations exist.\u003c/p\u003e"
            }
          ],
          "value": "IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic when certain configurations exist."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-1284",
              "description": "CWE-1284 Improper Validation of Specified Quantity in Input",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-04-30T21:48:11.642Z",
        "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "shortName": "ibm"
      },
      "references": [
        {
          "tags": [
            "vendor-advisory",
            "patch"
          ],
          "url": "https://www.ibm.com/support/pages/node/7269424"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eCustomers running any vulnerable affected level of an affected Program, V11.5, and V12.1, can download the special build containing the interim fix for this issue from Fix Central. These special builds are available based on the most recent level for each impacted release: V11.5.9. They can be applied to any affected level of the appropriate release to remediate this vulnerability.\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003cdiv\u003e\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\u003cstrong\u003eRelease\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eFixed in mod pack\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eAPAR\u003c/strong\u003e\u003c/td\u003e\u003ctd\u003e\u003cstrong\u003eDownload URL\u003c/strong\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eV11.5\u003c/td\u003e\u003ctd\u003eTBD\u003c/td\u003e\u003ctd\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/defect/aCIgJ0000008Msz/dt458000\" rel=\"nofollow\"\u003eDT458000\u003c/a\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eSpecial Build #79671 or later for V11.5.9 available at this link:\u003cbr\u003e\u003ca href=\"https://www.ibm.com/support/pages/node/7087189\" rel=\"noopener noreferrer nofollow\"\u003ehttps://www.ibm.com/support/pages/node/7087189\u003c/a\u003e\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003e\u003cp\u003eV12.1\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eV12.1.4\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003e\u003ca href=\"https://www.ibm.com/mysupport/s/defect/aCIgJ0000008Msz/dt458000\" rel=\"nofollow\"\u003eDT458000\u003c/a\u003e\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003c/td\u003e\u003ctd\u003e\u003cp\u003eLatest for V12.1.4 is available at this link:\u003cbr\u003e\u003ca href=\"https://www.ibm.com/support/pages/node/7267513\" rel=\"noopener noreferrer nofollow\"\u003ehttps://www.ibm.com/support/pages/node/7267513\u003c/a\u003e\u003c/p\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003c/div\u003e\u003cp\u003e\u003c/p\u003e\u003cp\u003eIBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability.\u003c/p\u003e"
            }
          ],
          "value": "Customers running any vulnerable affected level of an affected Program, V11.5, and V12.1, can download the special build containing the interim fix for this issue from Fix Central. These special builds are available based on the most recent level for each impacted release: V11.5.9. They can be applied to any affected level of the appropriate release to remediate this vulnerability.\n\n\n\n\n\nReleaseFixed in mod packAPARDownload URLV11.5TBD https://www.ibm.com/support/pages/node/7087189 \n\n\n\nV12.1\n\n\n\n\n\n\n\nV12.1.4\n\n\n\n\n\n\n\n https://www.ibm.com/support/pages/node/7267513 \n\n\n\n\n\n\n\n\n\nIBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability."
        }
      ],
      "title": "IBM\u00ae Db2\u00ae is vulnerable to a denial of service when fetching from certain tables under specific configurations",
      "workarounds": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eRemove registry variable DB2_EXTENDED_OPTIMIZATION=NLJN_OFLOW by:\u003c/p\u003e\u003cp\u003edb2set -im DB2_EXTENDED_OPTIMIZATION=\u003c/p\u003e"
            }
          ],
          "value": "Remove registry variable DB2_EXTENDED_OPTIMIZATION=NLJN_OFLOW by:\n\n\n\ndb2set -im DB2_EXTENDED_OPTIMIZATION="
        }
      ],
      "x_generator": {
        "engine": "ibm-cvegen"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
    "assignerShortName": "ibm",
    "cveId": "CVE-2025-14688",
    "datePublished": "2026-04-30T21:48:11.642Z",
    "dateReserved": "2025-12-14T03:20:30.962Z",
    "dateUpdated": "2026-05-27T16:33:29.099Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}