IBM Product Security Update Recommendation

IBM Product Security Update Recommendation

IBM has released security updates to address vulnerabilities discovered in several of its products.

  • The affected products are IBM WebSphere Application Server, IBM WebSphere Application Server - Liberty, IBM Tivoli System Automation Application Manager, IBM i, and IBM Documentation Offline.
  • CVE-2026-8400 is a vulnerability in IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty that allows a malicious IIOP server to load and instantiate arbitrary classes.
  • CVE-2026-11594, CVE-2026-11707, and CVE-2026-11383 are XSS (cross-site scripting) vulnerabilities occurring in the management console and login page of IBM WebSphere Application Server.
  • CVE-2026-16713 is a sensitive information exposure vulnerability in IBM Documentation Offline caused by the server being bound to unrestricted IP addresses.
  • IBM i contains denial-of-service (DoS) vulnerabilities such as CVE-2026-16982, CVE-2026-17004, CVE-2026-17199, CVE-2026-17229, and others; an authentication bypass vulnerability in CVE-2026-17197; arbitrary code execution vulnerabilities in CVE-2026-17206 and CVE-2026-17223, and a denial-of-service and authentication metadata tampering vulnerability in CVE-2026-17220.
  • IBM Documentation Offline is affected by a session token forgery vulnerability (CVE-2026-17468), an arbitrary file read vulnerability (CVE-2026-17473), CVE-2026-17481 and CVE-2026-17482, which involve arbitrary code execution.
  • Patches are provided with the latest updates and require the application of version-specific updates, Interim Fixes, or PTFs for each product. For example, IBM WebSphere Application Server requires version 8.5.5.31 Or later, or DT496796 Interim Fix; for 9.0, IBM SDK, Java Technology Edition 8 SR8 FP70 or later is required. IBM Documentation Offline requires version 1.5.1.
  • For IBM i, apply the relevant PTF as instructed on the reference site.