All CosmicBytez Labs articles tagged #IBM, across news, security advisories, how-to guides, and projects.
A high-severity XXE vulnerability in IBM App Connect Enterprise's SAP Adapter lets low-privileged users exfiltrate confidential data via crafted XML.
CVE-2026-18527 (CVSS 9.9) lets unauthenticated attackers hijack another user's session in IBM ARE for i's legacy GUI, gaining elevated privileges.
CVE-2026-3627 (CVSS 9.1) lets remote attackers run arbitrary SQL against IBM Concert 1.0.0-2.3.1 with no authentication, exposing the backend DB.
CVE-2026-19286 (CVSS 9.8) lets remote attackers execute arbitrary code on Langflow OSS 1.0.0-1.11.1 through the public A2A endpoint, no auth needed.
CVE-2026-19295 (CVSS 9.9) lets an authenticated Langflow user run arbitrary OS commands by crafting a flow, bypassing the custom-component lockdown.
IBM AIX 7.2/7.3 and PowerVM VIOS 4.1 have a critical flaw allowing remote attackers to overwrite arbitrary files. CVSS 9.1. Patch via IBM Fix Central.
IBM Documentation Offline versions 1.0.0–1.4.1 contain a critical path traversal flaw allowing remote code execution with a CVSS score of 9.8.
Critical cross-site scripting vulnerability in IBM WebSphere Application Server's administrative console login page enables unauthenticated remote attackers to hijack admin sessions.
Critical path traversal vulnerability in IBM App Connect Enterprise allows unauthenticated remote attackers to write arbitrary files on the system using dot-dot sequences in crafted URLs.
A critical broken access control flaw (CVSS 9.8) in IBM WebSphere Application Server 8.5 and 9.0 allows attackers to escalate privileges via the administrative console.
A critical pre-authentication unsafe deserialization flaw (CVSS 9.8) in IBM WebSphere Application Server 8.5 and 9.0 allows remote attackers to bypass authentication or execute arbitrary code.
A critical unquoted shell interpolation vulnerability (CVSS 9.1) in IBM Aspera Faspex 5 (versions 5.0.0–5.0.15.4) allows authenticated remote attackers to execute arbitrary code.
IBM Langflow OSS versions 1.0.0 through 1.10.1 contain hardcoded credentials used for inbound authentication and internal encryption, allowing...
IBM and Red Hat announced Project Lightwell — a $5 billion commitment to secure open-source supply chains using Anthropic's Mythos AI model, which found...
IBM DevOps Automation and IBM DevOps Loop fail to invalidate session IDs after expiration, allowing authenticated attackers to impersonate other users via...
IBM and Red Hat unveil Project Lightwell, a $5B commitment to securing open-source supply chains by fixing vulnerabilities without breaking production.