IBM Product Security Update Advisory

IBM Product Security Update Advisory

Overview


IBM has released security updates addressing several vulnerabilities in WebSphere Application Server, WebSphere Application Server – Liberty, IBM App Connect Enterprise, and IBM Enterprise Build of Quarkus. Users of these products must update to the latest version or apply the relevant APAR Interim Fix or Fix Pack.

Affected Products and Vulnerabilities


  • CVE-2026-9322, CVE-2026-10842: WebSphere Application Server 8.5.0.0 Through 8.5.5.30, WebSphere Application Server 9.0.0.0 Through 9.0.5.28, And WebSphere Application Server – Liberty 17.0.0.3 Through 26.0.0.7.
  • CVE-2026-11536: WebSphere Application Server 8.5.0.0 Through 8.5.5.29, WebSphere Application Server 9.0.0.0 Through 9.0.5.28.
  • CVE-2026-14519, CVE-2026-14522: IBM App Connect Enterprise 12.0.1.0 Through 12.0.12.27, And 13.0.1.0 Through 13.0.7.2.
  • CVE-2026-2482, CVE-2026-14980: IBM WebSphere Application Server – Liberty 17.0.0.3 Through 26.0.0.8.
  • CVE-2026-15435: IBM App Connect Enterprise 13.0.1.0 Or later through 13.0.7.2, 12.0.1.0 Or later through 12.0.12.27.
  • CVE-2026-16308: IBM Enterprise Build of Quarkus 3.27.1 Through 3.27.4.SP2, and 3.33.1 Through 3.33.2.SP2.

Vulnerability Details


  • Cross-Site Request Forgery (CSRF; a vulnerability that allows requests to be sent contrary to the user’s intent): CVE-2026-2482, CVE-2026-14980.
  • Denial of Service (DoS; a vulnerability that prevents the Service from functioning normally) caused by manipulated HTTP requests: CVE-2026-9322.
  • Bypassing security: CVE-2026-10842.
  • Remote code execution in the SOAP/JMX connector (a connection component for server management): CVE-2026-11536.
  • Arbitrary file read due to path traversal: CVE-2026-14519.
  • Arbitrary command execution due to improper handling of CRLF characters: CVE-2026-14522.
  • Arbitrary file write due to path traversal: CVE-2026-15435.
  • Denial of Service in Quarkus REST (REST API processing component): CVE-2026-16308.

Fixed Versions


  • CVE-2026-9322: WebSphere Application Server 8.5.5.31 Or later, 9.0.5.29 Or later, or APAR PH71670 Interim Fix; WebSphere Application Server – Liberty 26.0.0.8 Or later, or APAR PH71585 Interim Fix.
  • CVE-2026-10842: WebSphere Application Server 8.5.5.31 Or later, 9.0.5.29 Or later, or the APAR PH71893 Interim Fix; WebSphere Application Server – Liberty 26.0.0.8 Or later, or the APAR PH71916 Interim Fix.
  • CVE-2026-11536: WebSphere Application Server 8.5.5.30 Or later, 9.0.5.29 Or later, or APAR PH71714 Interim Fix.
  • CVE-2026-14519, CVE-2026-14522: IBM App Connect Enterprise 12.0.12.28 Or later, 13.0.8.0 Or later, or a Fix Pack that includes APAR IT49745.
  • CVE-2026-2482, CVE-2026-14980: IBM WebSphere Application Server – Liberty 26.0.0.9 Or later, or the APAR PH71678 Interim Fix.
  • CVE-2026-15435: IBM App Connect Enterprise 13.0.8.0 Or later, 12.0.12.28 Or later, or a Fix Pack that includes APAR IT49737.
  • CVE-2026-16308: IBM Enterprise Build of Quarkus 3.27.4.SP3 or later, 3.33.2.SP3 or later.

Note


The reference site includes IBM Security Bulletins for each vulnerability.