Vendor
SQL Injection Vulnerability in IBM Platform RTM
1 TTP 1 CVEIBM Platform RTM contains a SQL injection vulnerability that allows a remote, unauthenticated attacker to execute arbitrary SQL statements against the backend database, leading to potential unauthorized data access, modification, or deletion.
Integer Overflow Vulnerability in IBM MQ Request Processing (CVE-2026-11725)
1 CVEAn integer overflow vulnerability in IBM MQ's processing of MQINQ requests allows an authenticated attacker to trigger a denial of service or potentially execute arbitrary code.
Unauthenticated Remote Code Execution in IBM Guardium Data Protection
4 TTPs 1 CVEIBM Guardium Data Protection version 12.2 is vulnerable to a critical deserialization flaw allowing remote, unauthenticated attackers to execute arbitrary code (CVE-2026-81657).
IBM MQ Improper Validation Vulnerability (CVE-2026-11381)
1 CVEIBM MQ contains a vulnerability in the validation of message distribution list structures that allows an authenticated attacker to trigger a denial of service or potentially execute arbitrary code.
Stack Buffer Overflow in IBM MQ XA Transaction Processing
1 CVEIBM MQ is vulnerable to a stack buffer overflow triggered by malicious XA transaction identifiers, allowing an authenticated attacker to cause a denial of service or achieve arbitrary code execution.
Vulnerability in IBM MQ Cluster Command Message Validation
1 CVEIBM MQ contains a vulnerability (CVE-2026-10853) where improper cluster command message length validation allows authenticated attackers to cause a denial of service or remote code execution.
IBM MQ Java and JMS Client Deserialization Vulnerability
1 TTP 1 CVEAn authenticated attacker can execute arbitrary code on client applications by exploiting a deserialization filter bypass in IBM MQ Java and JMS client libraries.
Buffer Overflow Vulnerability in IBM MQ
2 TTPs 1 CVEIBM MQ is vulnerable to a buffer overflow during the processing of malformed compressed data, which can be leveraged by a remote attacker for denial of service or arbitrary code execution.
Path Traversal Vulnerability in IBM Cloud Pak for Data
1 TTP 1 CVEIBM Cloud Pak for Data 5.1.2 is vulnerable to a path traversal vulnerability via crafted URL requests that allow unauthenticated remote attackers to access arbitrary files on the system.
Heap Buffer Underflow in IBM MQ for HPE NonStop
1 TTP 1 CVEIBM MQ for HPE NonStop versions 8.1.0 through 8.1.0.40 contain a heap buffer underflow vulnerability in multi-segment message processing that allows authenticated attackers to execute arbitrary code or trigger denial of service.
CSRF Vulnerability in IBM Common Licensing Agent and ART
1 CVEIBM Common Licensing Agent and ART versions 9.0 through 9.0.0.2 contain a cross-site request forgery (CSRF) vulnerability that enables unauthenticated attackers to perform unauthorized actions on behalf of an authenticated user.
XML External Entity Injection in IBM MQ Classes for Java
1 TTP 1 CVEAn XML external entity injection vulnerability (CVE-2026-12666) in IBM MQ Classes for Java allows authenticated attackers to perform denial-of-service attacks or disclose sensitive host information by manipulating MQRFH2 headers.
Multiple Vulnerabilities in IBM MQ
2 CVEsIBM MQ is affected by multiple vulnerabilities, including CVE-2024-49033, CVE-2024-49034, and CVE-2024-49035, which could allow a remote attacker to execute arbitrary code, cause a denial of service, disclose sensitive information, or manipulate data.
Information Disclosure Vulnerability in IBM Sterling File Gateway
1 TTP 1 CVEIBM Sterling File Gateway contains an improper access control vulnerability (CVE-2026-19290) that allows remote attackers to obtain sensitive information.
IBM MQ XML External Entity Injection Vulnerability
1 TTP 1 CVEAn XML external entity injection vulnerability in IBM MQ allows authenticated attackers to perform arbitrary file reads or server-side request forgery during reply message processing.
XML External Entity Injection in IBM Business Automation Workflow
1 TTP 1 CVEIBM Business Automation Workflow contains a vulnerability in default programming artifacts that allows for XML External Entity (XXE) injection attacks, potentially enabling unauthorized file access or server-side request forgery.
Command Injection Vulnerability in IBM App Connect Enterprise
1 TTP 1 CVEIBM App Connect Enterprise versions 13.0.x and 12.0.x contain a command injection vulnerability (CVE-2026-17133) that allows local attackers to execute arbitrary OS commands.
Stack-Based Buffer Overflow in IBM Db2 DRDA Client Implementation
2 TTPs 1 CVEIBM Db2 versions 11.5.0-11.5.9 and 12.1.0-12.1.5 are vulnerable to a stack-based buffer overflow via malicious DRDA server responses, potentially leading to arbitrary command execution on clients.
Remote Code Execution in IBM DataStage
3 TTPs 1 CVEIBM DataStage on Cloud Pak for Data 5.4.0.0 is vulnerable to an OS command injection flaw allowing remote authenticated attackers to execute arbitrary code.
Container Escape Vulnerability in IBM Aspera Enterprise WebApps
1 TTP 1 CVEIBM Aspera Enterprise WebApps versions 1.0.0 through 1.0.5 are susceptible to a container escape vulnerability via unrestricted system calls, potentially allowing a local attacker to gain unauthorized host access.
XXE Vulnerability in IBM webMethods Integration Server
1 TTP 1 CVEIBM webMethods Integration Server 11.1 is vulnerable to an XML External Entity (XXE) injection flaw that allows unauthenticated attackers to exfiltrate sensitive files or trigger denial of service via memory exhaustion.
Path Traversal Vulnerability in IBM DataStage on Cloud Pak for Data
1 TTP 1 CVEIBM DataStage on Cloud Pak for Data version 5.4.0.0 is vulnerable to a path traversal flaw that allows a remote authenticated attacker to trigger a denial of service condition.
Path Traversal Vulnerability in IBM DataStage
2 TTPs 1 CVEIBM DataStage on Cloud Pak for Data 5.4.0.0 is vulnerable to path traversal during archive extraction, allowing an authenticated remote attacker to create arbitrary files on the host system.
Host Header Injection in IBM Common Licensing Agent and ART
1 rule 1 CVEIBM Common Licensing Agent and ART versions 9.0 through 9.0.0.2 are vulnerable to an unauthenticated remote redirect attack via improper HTTP Host header validation.
Denial of Service Vulnerability in libtpms
1 TTP 1 CVEA vulnerability in libtpms (CVE-2024-0230) allows an attacker on an adjacent network to trigger a denial of service condition, potentially leading to service instability.
SQL Injection in IBM Operational Decision Manager Leads to RCE
2 TTPs 1 CVEIBM Operational Decision Manager is vulnerable to an unauthenticated SQL injection allowing attackers to achieve remote code execution via web shell placement.
Authorization Bypass in IBM i DDM Target Dispatcher
1 CVEA vulnerability in the IBM i DDM target dispatcher allows remote attackers to manipulate database transactions due to improper authorization handling.
IBM ContextForge MCP Gateway SSRF via DNS Rebinding
1 TTP 1 CVEIBM ContextForge MCP Gateway is susceptible to server-side request forgery (SSRF) via DNS rebinding, allowing a remote authenticated attacker to access sensitive internal network information.
Information Disclosure Vulnerability in IBM Instana Agent Operator
1 TTP 1 CVEIBM Instana Agent Operator versions 1.0.303 through 1.0.323 contain a vulnerability involving missing namespace validation that allows an authenticated attacker to copy sensitive etcd mTLS credentials to an attacker-controlled namespace.
Information Disclosure via DNS Rebinding in IBM ContextForge MCP Gateway
1 TTP 1 CVEIBM ContextForge MCP Gateway versions 1.0.6 and earlier contain a DNS rebinding vulnerability that allows remote authenticated attackers to access sensitive information during tool invocation.
IBM Instana Agent Operator RBAC Hijacking Vulnerability
1 TTP 1 CVEAn authenticated tenant can perform privilege escalation in Kubernetes clusters using IBM Instana Agent Operator (Build 1.0.303 through 1.0.323) by creating a malicious Custom Resource that overwrites shared cluster-level RBAC objects.
XML External Entity Vulnerability in IBM App Connect Enterprise and Integration Bus
1 TTP 1 CVEIBM App Connect Enterprise and IBM Integration Bus for z/OS SAP Adapter components are susceptible to an XML External Entity (XXE) vulnerability, potentially allowing unauthenticated information disclosure or denial of service.
Hardcoded Credentials in IBM Netezza Software
1 TTP 1 CVEIBM Netezza Software versions 11.3.0.3 through 11.3.0.3 Interim Fix 002 contain hardcoded credentials, allowing unauthorized access to internal container registries.
Information Disclosure Vulnerability in IBM QRadar SIEM
1 TTP 1 CVEA vulnerability in IBM QRadar SIEM allows a remote, authenticated attacker to gain unauthorized access to sensitive information.
Privilege Escalation in IBM Application Runtime Expert for i
1 CVEIBM Application Runtime Expert (ARE) for i version 1R1M0 contains a vulnerability in its GUI component that allows an unauthenticated remote attacker to gain elevated privileges by masquerading as an authenticated user.
Information Disclosure Vulnerability in IBM Administration Runtime Expert for i
1 TTP 1 CVEIBM Administration Runtime Expert for i 1R1M0 contains an improper authentication enforcement vulnerability allowing a remote authenticated attacker to access sensitive information.
Local Privilege Escalation in IBM AIX and PowerVM VIOS via CVE-2026-16821
1 TTP 1 CVEA format string vulnerability in IBM AIX 7.2, 7.3, and PowerVM VIOS 4.1 allows local authenticated users to achieve privilege escalation.
SQL Injection Vulnerability in IBM Concert
1 TTP 1 CVEIBM Concert versions 1.0.0 through 2.3.1 are vulnerable to a remote SQL injection attack, allowing unauthenticated attackers to query, modify, or delete data in the back-end database.
Remote Code Execution in IBM Langflow OSS via A2A Endpoint
1 rule 8 TTPs 1 CVEIBM Langflow OSS versions 1.0.0 through 1.11.1 contain an unauthenticated remote code execution vulnerability in the A2A public endpoint.
Trestle Server-Side Template Injection via Custom Jinja2 Extensions
1 TTPThe Trestle command-line tool is vulnerable to Server-Side Template Injection (SSTI) due to the unsafe re-evaluation of untrusted Markdown content as Jinja2 template code.
Uncontrolled Resource Consumption Vulnerability in IBM AIX and PowerVM VIOS
1 TTP 1 CVEIBM AIX and PowerVM VIOS contain a remote, unauthenticated denial-of-service vulnerability (CVE-2026-19446) triggered by sending a crafted UDP packet to an RPC service, resulting in system unavailability.
Authentication Bypass Vulnerability in IBM DS8000 Series Storage
1 TTP 1 CVEIBM DS8A00 and DS8900F storage systems are vulnerable to an authentication bypass via improper encoding of DSCLI command output, potentially enabling information disclosure or denial of service.
IBM Portieris Image Policy Enforcement Bypass
1 TTP 1 CVEIBM Portieris versions 0.5.0 through 0.14.2 contain a missing authorization vulnerability that allows authenticated attackers to bypass image policy enforcement by manipulating pod owner references.
Arbitrary Code Execution in IBM PowerVM Hypervisor Service Processor
1 TTP 1 CVEA vulnerability in the IBM PowerVM Hypervisor service processor mailbox interface allows an authenticated attacker to execute arbitrary code within the host firmware runtime.
Critical RCE Vulnerability in IBM Power Systems Firmware ASMI
2 TTPs 1 CVEIBM Power Systems Firmware contains a stack-based buffer overflow in the ASMI web interface, allowing an unauthenticated attacker to achieve arbitrary code execution on the Flexible Service Processor.
Stack-Based Buffer Overflow in IBM Power Firmware
2 TTPs 1 CVEA stack-based buffer overflow in the firmware boot image validation process of specific IBM Power Firmware versions allows attackers with service processor access to execute arbitrary code on the host system.
Exposure of Certificate Authority Private Keys in IBM AIX and PowerVM VIOS
3 TTPs 1 CVEIBM AIX 7.2, 7.3, and PowerVM VIOS 4.1 contain intermediate CA private keys within publicly available update files, potentially allowing remote attackers to bypass security restrictions.
Cross-Site Scripting Vulnerability in IBM App Connect Enterprise
1 TTP 1 CVEIBM App Connect Enterprise contains a vulnerability, identified as CVE-2024-44280, that allows a remote, anonymous attacker to execute Cross-Site Scripting (XSS) attacks within the context of the affected application.
IBM Langflow Desktop Security Bypass Vulnerability
1 TTPA vulnerability in IBM Langflow Desktop allows remote, unauthenticated attackers to bypass established security measures, potentially leading to unauthorized access within the application environment.
IBM i Remote Denial-of-Service via Buffer Overflow (CVE-2026-18846)
1 CVEIBM i versions 7.3 through 7.6 are susceptible to a buffer overflow vulnerability allowing unauthenticated remote attackers to trigger a denial-of-service condition via malformed requests.
IBM i TOCTOU Race Condition Vulnerability
1 TTP 1 CVEIBM i versions 7.3 through 7.6 contain a time-of-check time-of-use (TOCTOU) race condition that allows a local authenticated attacker to gain unauthorized access to sensitive files.
Arbitrary Code Execution in IBM i via Untrusted Search Path
1 TTP 1 CVEAn untrusted search path vulnerability (CVE-2026-16674) in IBM i versions 7.3 through 7.6 allows a remote authenticated attacker to achieve arbitrary code execution.
Hardcoded Authentication Token in IBM Storage Scale GUI
2 TTPs 1 CVEIBM Storage Scale versions 5.2.3.0 through 5.2.3.8 and 6.0.0.0 through 6.0.1.0 contain a hardcoded token used for inter-node communication and REST API authentication, allowing potential unauthenticated access to the GUI.
Authentication Bypass Vulnerability in IBM Langflow OSS
1 TTP 1 CVEIBM Langflow OSS versions 1.0.0 through 1.9.6 are vulnerable to an authentication bypass flaw due to improper restriction of excessive authentication attempts, allowing remote attackers to potentially compromise user accounts.
Remote Code Execution in IBM Documentation Offline
2 TTPs 1 CVEIBM Documentation Offline versions 1.0.0 through 1.4.1 are vulnerable to remote code execution due to improper control of file paths (CVE-2026-17482), allowing unauthenticated attackers to compromise affected systems.
IBM i Local Privilege Escalation Vulnerability (CVE-2026-18071)
1 TTP 1 CVEIBM i versions 7.3 through 7.6 contain a privilege management vulnerability that allows authenticated local attackers to achieve elevated system privileges.
IBM i Security Restriction Bypass via Improper Identity Validation
1 TTP 1 CVEIBM i versions 7.3 through 7.6 contain a high-severity vulnerability (CVE-2026-17197) that allows remote, unauthenticated attackers to bypass security restrictions due to improper validation of client-asserted identity.
Integer Underflow Vulnerability in IBM i
3 TTPs 1 CVEIBM i versions 7.3 through 7.6 are vulnerable to an integer underflow flaw (CVE-2026-17485) that could allow a remote, unauthenticated attacker to cause a denial of service or perform an out-of-bounds read to access sensitive information.
Local Privilege Escalation in IBM Informix Dynamic Server
1 TTP 1 CVEA local privilege escalation vulnerability in the oninit setuid-root utility of IBM Informix Dynamic Server 14.10 and 15.0 allows local authenticated users to gain elevated system privileges.
Arbitrary Code Execution in IBM i Access Client Solutions
3 TTPs 1 CVEIBM i Access Client Solutions versions 1.1.2.0 through 1.1.9.13 contain a local arbitrary code execution vulnerability on Windows due to insecure file permissions on a configuration file.
Privilege Escalation Vulnerability in IBM Db2
1 TTP 1 CVEIBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5 are susceptible to privilege escalation due to improper authorization when processing crafted SQL queries.
Improper Authentication in IBM DOORS Next
1 TTP 1 CVEIBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 contains an improper authentication vulnerability that allows authenticated users to bypass security logic and perform unauthorized actions.
Remote Code Execution in IBM Informix via sq_sgkprepare
2 TTPs 1 CVEA critical buffer-related vulnerability (CVE-2026-13361) in IBM Informix allows remote, unauthenticated attackers to achieve code execution via the SQL interface by exploiting an unchecked length field in the oninit process.
Cryptographic Validation Vulnerability in IBM Security Verify Access
1 CVEIBM Security Verify Access and IBM Verify Identity Access contain a vulnerability in the Reverse Proxy component involving weak cryptographic validation of user-supplied data.
Privilege Escalation Vulnerability in IBM WebSphere Application Server Liberty
1 TTP 1 CVEIBM WebSphere Application Server Liberty versions 17.0.0.3 through 26.0.0.8 contain a privilege escalation vulnerability when using Liberty collective management features.
Remote Command Injection in IBM Db2 Mirror for i
2 TTPs 1 CVEIBM Db2 Mirror for i versions 7.4 through 7.6 contain a critical command injection vulnerability allowing remote unauthenticated attackers to execute arbitrary system commands.
Uncontrolled Search Path Vulnerability in IBM i
3 TTPs 5 CVEsIBM i versions 7.3 through 7.6 contain an uncontrolled search path element vulnerability that allows a remote authenticated attacker to execute arbitrary code with elevated privileges.
Multiple Vulnerabilities in IBM QRadar SIEM
3 TTPsIBM QRadar SIEM contains multiple vulnerabilities that enable a remote authenticated attacker to escalate privileges, execute arbitrary code, disclose information, and bypass security controls.
SSRF Vulnerability in IBM Application Gateway Operator
1 TTP 1 CVEIBM Application Gateway Operator versions 22.2 through 26.06 contain a Server-Side Request Forgery vulnerability due to improper URL validation in custom resources, potentially allowing unauthorized access to internal resources.
IBM WebSphere Application Server ORB Unsafe Reflection Vulnerability
1 TTP 1 CVEA vulnerability in the Object Request Broker (ORB) component of IBM SDK for Java allows an unauthenticated attacker to trigger remote code execution via arbitrary class instantiation.
XXE Injection Vulnerability in IBM QRadar
1 TTP 1 CVEIBM QRadar contains an XML External Entity (XXE) injection vulnerability in the event processing pipeline that allows unauthenticated attackers to read arbitrary files from the system.
Multiple Denial of Service Vulnerabilities in IBM Tivoli Netcool/OMNIbus
1 TTPMultiple Denial of Service vulnerabilities in IBM Tivoli Netcool/OMNIbus, potentially involving vulnerable Immutable.js libraries, allow unauthenticated remote attackers to disrupt service availability.
Path Traversal Vulnerability in IBM Langflow OSS
1 rule 1 CVEIBM Langflow OSS versions 1.0.0 through 1.10.1 are vulnerable to a path traversal flaw (CVE-2026-12942) that allows unauthenticated remote attackers to read arbitrary files from the hosting system.
Stack-based Buffer Overflow in IBM Db2 setgid Helper
1 rule 1 TTP 1 CVEIBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4 contain a buffer overflow vulnerability in the db2flacc setgid helper that allows local attackers to escalate privileges.
Critical OS Command Injection in IBM Hardware Management Console
1 CVEA critical unauthenticated command injection vulnerability (CVE-2026-12943) in IBM HMC and Novalink allows remote attackers to execute arbitrary commands with elevated privileges.
Critical Deserialization Vulnerability in IBM webMethods Integration
1 TTP 1 CVEIBM webMethods Integration (on-premises) versions 10.11 and 10.15 contain a critical deserialization vulnerability (CVE-2026-12118) that enables unauthenticated remote code execution.
Authorization Bypass Vulnerability in IBM Langflow OSS
1 TTP 1 CVEIBM Langflow OSS versions 1.0.0 through 1.10.1 contain an authorization bypass vulnerability (CVE-2026-12945) allowing authenticated users to access and manipulate build jobs of other users.
IBM PowerVM Hypervisor Memory Integrity Vulnerability
1 CVEA buffer overflow vulnerability in IBM PowerVM Hypervisor allows a local attacker with low privileges to trigger system crashes or compromise OS memory integrity via crafted hypervisor calls.
Authentication Bypass Vulnerability in IBM WebSphere Application Server
2 CVEsA critical authentication bypass vulnerability (CVE-2026-10842) allows remote, unauthenticated attackers to circumvent security constraints in IBM WebSphere Application Server and Liberty versions.
Unauthenticated Remote Code Execution in IBM Langflow OSS
3 TTPs 1 CVEIBM Langflow OSS versions 1.0.0 through 1.10.1 are susceptible to unauthenticated remote code execution due to improper sanitization of environment variables in the MCP stdio launcher.
Denial of Service Vulnerability in IBM Enterprise Build of Quarkus
1 TTP 1 CVEA resource exhaustion vulnerability (CVE-2026-16308) in IBM Enterprise Build of Quarkus allows remote, unauthenticated attackers to cause a denial of service via unbounded accumulation of multipart MIME headers.
Arbitrary Code Execution in IBM Aspera Desktop App via DLL Hijacking
1 TTP 1 CVEIBM Aspera Desktop App versions 1.0.5 through 1.0.19 are susceptible to arbitrary code execution through a DLL hijacking vulnerability during application start-up.
Denial of Service Vulnerability in IBM WebSphere Application Server - Liberty
1 CVEA remote unauthenticated denial-of-service vulnerability in IBM WebSphere Application Server - Liberty allows attackers to cause excessive memory consumption via crafted requests.
Critical Path Traversal Vulnerability in IBM App Connect Enterprise (CVE-2026-15435)
1 rule 1 CVEIBM App Connect Enterprise contains a critical path traversal vulnerability (CVE-2026-15435) allowing remote, unauthenticated attackers to write arbitrary files to the system via crafted HTTP requests.
Reflected XSS in IBM Tivoli System Automation and WebSphere Application Server
1 rule 1 CVEIBM Tivoli System Automation Application Manager 4.1 and WebSphere Application Server are affected by a reflected cross-site scripting vulnerability in the administrative console login page that allows unauthenticated attackers to execute arbitrary JavaScript.
IBM WebSphere Application Server Security Bypass Vulnerability
1 TTPIBM WebSphere Application Server and Liberty are vulnerable to a security bypass flaw that permits remote, unauthenticated attackers to circumvent established security controls.
SSRF Vulnerability in IBM WebSphere Application Server
1 CVEIBM WebSphere Application Server and Liberty are vulnerable to unauthenticated Server-Side Request Forgery (SSRF) when the SIP container feature is enabled, allowing attackers to perform unauthorized requests to internal services.
IBM WebSphere Application Server and Liberty Multiple Vulnerabilities
5 TTPsMultiple vulnerabilities exist in IBM WebSphere Application Server and IBM WebSphere Application Server Liberty that an attacker can exploit to execute arbitrary code, escalate privileges, perform denial of service attacks, disclose sensitive information, manipulate files, conduct cross-site scripting attacks, and bypass security measures.
IBM WebSphere Application Server Liberty: Multiple Vulnerabilities Enable Denial of Service
1 TTPMultiple vulnerabilities exist in IBM WebSphere Application Server Liberty that an attacker can exploit to perform a Denial of Service attack.
IBM WebSphere Application Server Liberty Path-Segment Injection Vulnerability (CVE-2026-15280)
1 CVEA path-segment injection vulnerability (CVE-2026-15280) in the collective routing mechanism of IBM WebSphere Application Server - Liberty versions 17.0.0.3 through 26.0.0.8 ND Collective Controller allows an unauthenticated attacker to inject arbitrary path segments, potentially leading to information disclosure.
CVE-2026-14996: IBM Aspera Faspex 5 Session Management Vulnerability
1 TTP 1 CVECVE-2026-14996 details a high-severity vulnerability (CVSS v3.1 8.2, CWE-613) in IBM Aspera Faspex 5 versions 5.0.0 through 5.0.15.4 that allows unauthenticated, remote attackers to exploit insufficient session management, leading to high confidentiality impact and low integrity impact.
IBM WebSphere Application Server Unsafe Deserialization Vulnerability
2 TTPs 1 CVEA critical unsafe deserialization vulnerability, CVE-2026-14974, in IBM WebSphere Application Server versions 8.5 and 9.0 traditional, allows a remote attacker to execute arbitrary code by processing specially crafted untrusted data, potentially leading to full system compromise.
IBM Instana Node.js Tracer Vulnerable to Prototype Pollution (CVE-2026-14893)
1 CVE 2 IOCsA high-severity prototype pollution vulnerability, CVE-2026-14893, exists in the IBM Instana Node.js tracer component (@instana/core version 6.2.1) affecting IBM Observability with Instana Agent builds 1.0.303 through 1.0.320, allowing an attacker to modify critical application behavior through the configuration normalization API.
IBM Langflow OSS Vulnerability Allows FAISS Namespace Reuse and Information Disclosure (CVE-2026-13442)
5 TTPs 1 CVEA critical vulnerability, CVE-2026-13442, in IBM Langflow OSS versions 1.0.0 through 1.10.1 enables an authenticated attacker to reuse other users' FAISS namespaces, leading to cross-user information disclosure of owner-only vector content and potential limited integrity impact via persistent poisoning of query results.
IBM Aspera Desktop App Path Traversal Vulnerability (CVE-2026-14973)
1 TTP 1 CVEThe IBM Aspera Desktop App (versions 1.0.5 through 1.0.19) is affected by a path traversal vulnerability (CWE-22) which allows files to be written outside of the user's selected download destination, leading to high integrity and confidentiality impacts through arbitrary file write operations, and requires user interaction to exploit.
CVE-2026-14959: IBM Aspera Faspex 5 Remote Code Execution via Shell Command Injection
2 TTPs 1 CVEA critical vulnerability, CVE-2026-14959, in IBM Aspera Faspex 5 (versions 5.0.0 through 5.0.15.4) allows a remote authenticated attacker to execute arbitrary code due to a shell command injection flaw, potentially leading to full system compromise and significant data loss or service disruption.
IBM Aspera Faspex 5 Remote Code Execution Vulnerability (CVE-2026-14958)
1 rule 2 TTPs 1 CVEA critical remote code execution vulnerability (CVE-2026-14958) in IBM Aspera Faspex 5, affecting versions 5.0.0 through 5.0.15.4, allows a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation, posing a significant risk of system compromise.
IBM WebSphere Application Server Liberty Denial of Service Vulnerability (CVE-2026-16192)
2 CVEsA denial of service vulnerability, CVE-2026-16192, affects IBM WebSphere Application Server - Liberty versions 17.0.0.3 through 26.0.0.8 when the `restConnector-2.0` feature is enabled, allowing an unauthenticated attacker to cause service unavailability.
IBM WebSphere Application Server Authentication Bypass Vulnerability (CVE-2026-16184)
5 TTPs 7 CVEs 5 IOCsA remote attacker can bypass authentication in IBM WebSphere Application Server versions 9.0 and 8.5 by sending a crafted unauthenticated request, potentially leading to unauthorized access and impact on confidentiality, integrity, and availability.
SQL Injection Vulnerability in IBM Sterling B2B Integrator and File Gateway (CVE-2026-7769)
3 TTPs 1 CVEA remote attacker can exploit CVE-2026-7769, an SQL injection vulnerability in IBM Sterling B2B Integrator and IBM Sterling File Gateway, to send specially crafted SQL statements, allowing them to view, add, modify, or delete information in the backend database.
Unusual Child Process Execution by Web Servers on Linux
2 rules 5 TTPs 13 IOCsThis detection rule identifies suspicious child process executions originating from web server processes on Linux systems, indicating that attackers may have exploited web application vulnerabilities such as command injection or remote file inclusion to establish persistence or execute malicious commands.
Unusual Command Execution via Linux Web Server Processes
1 rule 4 TTPsThis brief details how attackers exploit vulnerable web applications or deploy webshells on Linux systems to achieve persistence by executing unusual shell commands from web server processes, potentially leading to payload downloads, reverse shells, or cron-like task implants.
Suspicious Command Execution via Linux Web Server
1 rule 14 TTPsThis brief describes how attackers exploit vulnerabilities in web applications to execute suspicious shell commands via web server processes on Linux, enabling persistence, discovery, credential access, and reverse shell establishment, which can lead to full system compromise and data exfiltration.
IBM DB2: Multiple Vulnerabilities
2 TTPsMultiple vulnerabilities in IBM DB2 allow an attacker to perform a Denial of Service (DoS) attack and execute arbitrary code, which could lead to system disruption or full compromise.
Multiple Vulnerabilities in IBM Langflow Desktop OSS
6 TTPsAn attacker can exploit multiple vulnerabilities in IBM Langflow Desktop OSS to gain administrator privileges, execute arbitrary code, bypass security measures, manipulate and disclose data, or cause a denial-of-service condition, leading to full system compromise and data integrity/confidentiality breaches.
IBM Engineering AI Hub Information Disclosure via URL Session Tokens (CVE-2026-15322)
1 TTP 1 CVEA remote attacker can exploit CVE-2026-15322 in IBM Engineering AI Hub versions 1.0.0, 1.1.0, and 1.2.0 to obtain sensitive session tokens exposed in URLs, potentially leading to unauthorized access and information disclosure.
IBM Langflow OSS Command Injection Vulnerability
1 rule 2 TTPs 1 CVEAn authenticated attacker can exploit CVE-2026-14499 in IBM Langflow OSS versions 1.0.0 through 1.10.1 due to improper validation of user input in the Python Interpreter component, leading to arbitrary command execution with elevated privileges.
IBM Storage Protect Client Heap Buffer Overflow Allows Remote Code Execution
2 TTPs 1 CVEIBM Storage Protect Client versions 8.1.0.0 through 8.1.27.1 and 8.2.0.0 through 8.2.1.0 are vulnerable to CVE-2026-13473, a heap-based buffer overflow caused by improper bounds checking, allowing a remote attacker to execute arbitrary code or crash the server.
IBM Langflow OSS Remote Code Execution via Deserialization
1 rule 5 TTPs 7 CVEs 1 IOCIBM Langflow OSS versions 1.0.0 through 1.10.0 contain a critical deserialization vulnerability (CVE-2026-8476) in its disk-based caching mechanism, which uses Python's unsafe `pickle.loads()` function without proper validation, allowing attackers to process malicious pickle payloads and achieve arbitrary code execution with the privileges of the Langflow server process, leading to complete system compromise.
IBM Engineering AI Hub Cross-site Scripting Vulnerability (CVE-2026-15091)
2 TTPs 1 CVEA critical cross-site scripting (XSS) vulnerability, identified as CVE-2026-15091 with a CVSS v3.1 score of 9.3, affects IBM Engineering AI Hub versions 1.0.0, 1.1.0, and 1.2.0, allowing a remote attacker to execute arbitrary scripts due to improper input neutralization during web page generation.
IBM PowerVM Novalink Vulnerable to Denial of Service via Specially-Crafted Request
1 TTP 1 CVE 1 IOCIBM PowerVM Novalink is vulnerable to CVE-2026-9171, a denial-of-service attack where a remote unauthenticated attacker can send a specially-crafted request to cause the server to consume excessive memory resources, leading to system unavailability.
IBM Langflow OSS Code Injection Vulnerability in ToolGuard (CVE-2026-9135)
3 TTPs 1 CVEAn authenticated attacker can exploit CVE-2026-9135, a code injection vulnerability in IBM Langflow OSS versions 1.0.0 through 1.9.2, to bypass security controls and achieve arbitrary Python code execution on the backend through unvalidated dynamic CodeInput fields in the ToolGuard integration, potentially escalating privileges via cross-tenant flow manipulation.
IBM Langflow OSS Improper Authentication Vulnerability
2 rules 5 TTPs 3 CVEsA remote attacker can gain full administrative access to IBM Langflow OSS versions 1.0.0 through 1.10.0 by exploiting an improper authentication vulnerability. The /api/v1/login/auto_login endpoint, when the default AUTO_LOGIN configuration is enabled, issues long-lived superuser bearer tokens without requiring authentication. This allows an unauthenticated network attacker to obtain these tokens and achieve superuser privileges. Additionally, permissive Cross-Origin Resource Sharing (CORS) settings could expose these tokens to unintended origins, exacerbating the risk.
IBM Db2 Remote Code Execution via JDBC URL Vulnerability (CVE-2026-9762)
2 TTPs 1 CVEA critical remote code execution vulnerability, identified as CVE-2026-9762, exists in IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4, allowing attackers to execute arbitrary code if a JDBC URL is under user control, categorized as an improper control of code generation.
IBM Langflow OSS Unauthenticated Remote Code Execution via Chained API Endpoints (CVE-2026-9198)
1 rule 3 TTPs 11 CVEs 2 IOCsUnauthenticated attackers can achieve Remote Code Execution (RCE) on default IBM Langflow OSS deployments, versions 1.0.0 through 1.10.0, by chaining access to the `/api/v1/auto_login` endpoint, which mints SUPERUSER tokens, with the `/api/v1/validate/code` endpoint, which executes user-supplied code via `exec()`.
IBM Operational Decision Manager: Multiple Vulnerabilities Reported
4 TTPsMultiple critical vulnerabilities in IBM Operational Decision Manager allow an attacker to achieve arbitrary code execution, elevate privileges, perform denial of service attacks, disclose information, manipulate files, and bypass security measures.
CVE-2026-3144 - IBM API Connect Default Credentials Vulnerability
1 TTP 1 CVEIBM API Connect versions 12.1.0.0 through 12.1.0.3 are vulnerable to unauthorized access due to the use of default credentials, allowing an attacker to gain initial access to the application before the system enforces a credential update.
Unauthenticated SQL Injection in IBM API Connect (CVE-2026-9074)
1 rule 3 TTPs 1 CVEIBM API Connect versions 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 are vulnerable to an unauthenticated SQL injection (CVE-2026-9074) in the password reset functionality, potentially leading to unauthorized data access or authentication bypass.
Multiple Vulnerabilities in IBM Operational Decision Manager
4 TTPsMultiple vulnerabilities in IBM Operational Decision Manager can be exploited by a remote, unauthenticated attacker, allowing them to bypass security restrictions, achieve remote code execution, and cause a denial of service condition.
IBM WebSphere Application Server: Authenticated Remote Action Execution Vulnerability
1 TTPA vulnerability in IBM WebSphere Application Server allows a remote, authenticated attacker to execute arbitrary actions on the server, potentially leading to a compromise of the host system.
Unusual Child Process Execution from Linux Web Servers
2 rules 4 TTPsThis rule detects unusual child process executions originating from web server processes on Linux systems, which attackers may use to maintain persistence on a compromised system by exploiting web server vulnerabilities.
Suspicious Command Execution via Web Server on Linux
2 rules 3 TTPsIdentifies suspicious command executions via a web server on Linux systems, which may suggest a vulnerability and remote shell access.
Multiple Vulnerabilities in IBM Business Automation Workflow
2 rules 2 TTPsMultiple vulnerabilities in IBM Business Automation Workflow can be exploited by an attacker to bypass security measures, conduct a denial of service attack, disclose information, manipulate files, and conduct a cross-site scripting attack.
Multiple Vulnerabilities in IBM App Connect Enterprise
2 rulesMultiple vulnerabilities in IBM App Connect Enterprise could allow an attacker to bypass security measures, manipulate data, disclose sensitive information, cause a denial-of-service condition, or perform other unspecified attacks.
IBM DB2 Multiple Vulnerabilities Leading to Denial of Service
2 rules 1 TTPA remote, authenticated attacker can exploit multiple vulnerabilities in IBM DB2 to perform a denial of service attack, potentially disrupting database services.
CVE-2026-8180: IBM Aspera High-Speed Transfer Denial of Service
2 rules 1 TTP 1 CVEIBM Aspera High-Speed Transfer Endpoint and Server versions 3.7.4 through 4.4.7 Fix Pack 1 are vulnerable to a denial-of-service (DoS) attack where an unauthenticated user can crash the asperahttpd service.
CVE-2026-8179 - IBM Aspera High-Speed Transfer Endpoint and Server Buffer Overflow
2 rules 1 TTP 1 CVEIBM Aspera High-Speed Transfer Endpoint and Server 3.7.4 through 4.4.7 Fix Pack 1 are vulnerable to a buffer overflow in the asperahttpd component, potentially allowing an authenticated user to execute arbitrary code.
IBM Langflow OSS Uncontrolled Resource Consumption Denial-of-Service (CVE-2026-7528)
2 rules 1 TTP 1 CVEIBM Langflow OSS versions 1.0.0 through 1.9.0 are vulnerable to a denial-of-service (DoS) attack due to uncontrolled resource consumption as tracked by CVE-2026-7528.
IBM Operations Analytics and SmartCloud Analytics Default Password Vulnerability (CVE-2026-7365)
2 rules 1 TTP 1 CVEIBM Operations Analytics - Log Analysis and IBM SmartCloud Analytics - Log Analysis use default passwords from the manufacturing process, potentially allowing attackers to bypass authentication.
IBM Controller Hard-Coded Credentials Vulnerability (CVE-2026-5065)
2 rules 1 TTP 1 CVEIBM Controller versions 11.0.1, 11.1.0, 11.1.1, and 11.1.2 are vulnerable to hard-coded credentials (CVE-2026-5065), potentially allowing unauthorized access and control of the application.
IBM Netezza Performance Server Replication Services Privilege Escalation (CVE-2026-3623)
2 rules 1 TTP 1 CVEIBM Netezza Performance Server Replication Services versions 3.0.2.0 through 3.0.5.0 allows an attacker with low-privileged access to escalate their privileges to root, leading to complete system compromise.
CVE-2026-3366 - IBM InfoSphere Optim Test Data Fabrication Path Traversal
2 rules 1 TTP 1 CVEIBM InfoSphere Optim Test Data Fabrication versions 1.0.0 through 1.0.2.7 are susceptible to a path traversal vulnerability (CVE-2026-3366), allowing a remote attacker to send a specially crafted URL request containing 'dot dot' sequences (/../) to view arbitrary files on the system.
IBM Db2 Vulnerable to Denial-of-Service via Crafted Query (CVE-2026-1718)
2 rules 1 TTP 1 CVEIBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4 are vulnerable to a denial-of-service (DoS) attack via a specially crafted query when autonomous transactions are enabled, potentially leading to service disruption.
IBM QRadar Vulnerability CVE-2024-56462 Allows Privilege Escalation via Malicious Backup Upload
2 rules 1 TTP 1 CVEIBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 002 is vulnerable to CVE-2024-56462, enabling a privileged user to upload a malicious backup archive that, upon restoration, leads to unauthorized access to the underlying operating system.
CVE-2026-8175: IBM Aspera High-Speed Transfer Endpoint and Server Buffer Overflow
2 rules 3 TTPs 1 CVEIBM Aspera High-Speed Transfer Endpoint and Server are vulnerable to a buffer overflow in the asperahttpd component, potentially leading to denial of service, authentication bypass, or remote code execution.
IBM Langflow OSS Remote Code Execution Vulnerability (CVE-2026-7524)
2 rules 1 TTP 1 CVEIBM Langflow OSS versions 1.0.0 through 1.9.1 are vulnerable to remote code execution (CVE-2026-7524) due to improper validation of symbolic links during archive extraction, potentially allowing an attacker to execute arbitrary code on the system.
Multiple Vulnerabilities in IBM DB2
2 rules 3 TTPsMultiple vulnerabilities in IBM DB2 allow a remote, authenticated, or local attacker to disclose information, bypass security measures, or cause a denial of service.
CVE-2026-4051: IBM Engineering Lifecycle Management Remote Code Execution
2 rules 1 TTP 1 CVEIBM Engineering Lifecycle Management 7.0.3 through Interim Fix 021, 7.1.0 through Interim Fix 009, and 7.2.0 through Interim Fix 001 could allow an attacker with administrative privileges to execute remote code due to an exposed method that is not properly restricted, potentially leading to complete system compromise.
CVE-2026-3660: IBM Engineering Lifecycle Management Unauthenticated Remote Access
2 rules 1 TTP 1 CVEIBM Engineering Lifecycle Management versions 7.0.3 through Interim Fix 021, 7.1.0 through Interim Fix 009, and 7.2.0 through Interim Fix 001 are vulnerable to an unauthenticated remote attacker who can update server property files, leading to unauthorized access to the application.
CVE-2026-3603: IBM Engineering Lifecycle Management XXE Vulnerability
2 rules 1 TTP 1 CVEIBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 are vulnerable to XML external entity injection (XXE), allowing an authenticated attacker to expose sensitive information or consume memory resources.
CVE-2026-8834: IBM HTTP Server Buffer Overflow Vulnerability
2 rules 3 TTPs 1 CVEIBM HTTP Server 8.5 and 9.0 are vulnerable to a heap-based buffer overflow, allowing a privileged, authenticated user to execute arbitrary code or cause a denial of service.
CVE-2026-9170: IBM WebSphere Application Server and Liberty Improper Input Validation Vulnerability
2 rules 2 TTPs 1 CVEIBM WebSphere Application Server and WebSphere Liberty versions 8.5 and 9.0 are vulnerable to denial of service and potential remote code execution due to improper input validation as described in CVE-2026-9170.
CVE-2026-8856 - IBM HTTP Server Denial of Service Vulnerability
2 rules 1 TTP 1 CVEIBM HTTP Server 8.5 and 9.0 is vulnerable to a denial of service (DoS) in configurations where an attacker possesses write access to server configuration files, as tracked by CVE-2026-8856.
CVE-2026-8855: IBM HTTP Server RCE and DoS via TLS Mutual Authentication
2 rules 2 TTPs 1 CVEIBM HTTP Server 8.5 and 9.0 are vulnerable to remote code execution and denial of service in configurations utilizing TLS mutual authentication (client authentication).
CVE-2026-8854 - IBM HTTP Server mod_mem_cache Denial-of-Service
2 rules 1 TTP 1 CVEIBM HTTP Server 8.5 and 9.0 are vulnerable to a denial-of-service (DoS) attack due to a flaw in the optional `mod_mem_cache` module that can be triggered remotely.
CVE-2026-8835: IBM HTTP Server Invalid Pointer Dereference Vulnerability
2 rules 1 TTP 1 CVEIBM HTTP Server versions 8.5 and 9.0 are susceptible to an invalid pointer dereference, potentially allowing a privileged, authenticated user to expose sensitive information or cause a denial of service.
CVE-2026-8620: IBM WebSphere Application Server HTTP Request Smuggling Vulnerability
2 rules 1 TTP 1 CVEIBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5 and 9.0 are vulnerable to HTTP request smuggling due to inconsistent interpretation of HTTP requests, potentially leading to unauthorized access and data manipulation.
CVE-2026-8633: IBM WebSphere Application Server RCE via Crafted Request
2 rules 1 TTP 1 CVEIBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty are vulnerable to remote code execution in the Web Server Plug-ins, through a specially crafted request (CVE-2026-8633).
IBM App Connect Enterprise Multiple Vulnerabilities
2 rules 3 TTPsA remote, anonymous attacker can exploit multiple vulnerabilities in IBM App Connect Enterprise to execute arbitrary program code, manipulate data, conduct cross-site scripting attacks, disclose confidential information, or cause a denial-of-service condition.
AI Agent Data Theft via Indirect Prompt Injection
1 rule 2 TTPsAttackers are leveraging indirect prompt injection against AI agents with access to private data, untrusted content, and external communication channels to steal sensitive information by embedding malicious instructions in content processed by the agent.
IBM DB2 Big SQL Multiple Vulnerabilities
2 rules 2 TTPsMultiple vulnerabilities in IBM DB2 Big SQL could allow an attacker to perform a denial of service attack and execute arbitrary code.
IBM WebSphere Application Server Liberty Vulnerability Allows Code Execution
2 rules 1 TTPAn authenticated remote attacker can exploit a vulnerability in IBM WebSphere Application Server Liberty to execute arbitrary program code on the target system.
Multiple Vulnerabilities in IBM SPSS Allow for XSS, DoS, and File Manipulation
2 rules 1 TTPMultiple vulnerabilities in IBM SPSS can be exploited by an attacker to perform cross-site scripting (XSS) attacks, denial of service attacks, and to manipulate files.
IBM Turbonomic prometurbo Agent Privilege Escalation via Excessive Permissions (CVE-2026-6389)
2 rules 2 TTPs 1 CVEIBM Turbonomic prometurbo agent versions 8.16.0 through 8.17.6 grants excessive cluster-wide permissions, including unrestricted read access to all secrets, allowing a compromised operator or service account to exfiltrate credentials, escalate privileges, and achieve full cluster compromise.
IBM Langflow Desktop Vulnerable to Remote Command Execution (CVE-2026-6543)
3 rules 1 TTP 1 CVEIBM Langflow Desktop versions 1.0.0 through 1.8.4 are vulnerable to remote command execution, allowing an attacker to execute arbitrary commands with the privileges of the Langflow process, potentially leading to sensitive data exposure and lateral movement.
IBM Langflow Desktop Unauthenticated Image Access via IDOR
2 rules 1 TTP 1 CVEIBM Langflow Desktop versions 1.0.0 through 1.8.4 are vulnerable to an indirect object reference (IDOR) vulnerability (CVE-2026-4503), allowing unauthenticated users to view other users' images due to a user-controlled key.
IBM WebSphere Liberty Identity Spoofing Vulnerability (CVE-2026-3621)
2 rules 1 TTP 1 CVEIBM WebSphere Application Server Liberty versions 17.0.0.3 through 26.0.0.4 are susceptible to identity spoofing when applications are deployed without proper authentication and authorization configurations, potentially leading to unauthorized access and privilege escalation.
IBM Total Storage Service Console (TSSC) / TS4500 IMC Unauthenticated Remote Command Execution
2 rules 1 TTP 1 CVEAn unauthenticated user can execute arbitrary commands with normal user privileges on vulnerable IBM Total Storage Service Console (TSSC) / TS4500 IMC versions due to improper validation of user-supplied input, as identified by CVE-2026-5935.
Process Execution from Suspicious Windows Directories
2 rules 1 TTPAdversaries may execute processes from unusual default Windows directories to masquerade malware and evade defenses by blending in with trusted paths, making malicious activity harder to detect.