IBM Product Security Update Recommendation
IBM has released security updates to address vulnerabilities discovered in several of its products.
- The affected products are
IBM WebSphere Application Server,IBM WebSphere Application Server - Liberty,IBM Tivoli System Automation Application Manager,IBM i, andIBM Documentation Offline. CVE-2026-8400is a vulnerability inIBM WebSphere Application ServerandIBM WebSphere Application Server - Libertythat allows a maliciousIIOPserver to load and instantiate arbitrary classes.CVE-2026-11594,CVE-2026-11707, andCVE-2026-11383areXSS(cross-site scripting) vulnerabilities occurring in the management console and login page ofIBM WebSphere Application Server.CVE-2026-16713is a sensitive information exposure vulnerability inIBM Documentation Offlinecaused by the server being bound to unrestricted IP addresses.IBM icontains denial-of-service (DoS) vulnerabilities such asCVE-2026-16982,CVE-2026-17004,CVE-2026-17199,CVE-2026-17229, and others; an authentication bypass vulnerability inCVE-2026-17197; arbitrary code execution vulnerabilities inCVE-2026-17206andCVE-2026-17223, and a denial-of-service and authentication metadata tampering vulnerability inCVE-2026-17220.IBM Documentation Offlineis affected by a session token forgery vulnerability (CVE-2026-17468), an arbitrary file read vulnerability (CVE-2026-17473),CVE-2026-17481andCVE-2026-17482, which involve arbitrary code execution.- Patches are provided with the latest updates and require the application of version-specific updates,
Interim Fixes, orPTFsfor each product. For example,IBM WebSphere Application Serverrequires version8.5.5.31Or later, orDT496796 Interim Fix; for9.0,IBM SDK, Java Technology Edition 8 SR8 FP70or later is required.IBM Documentation Offlinerequires version1.5.1. - For
IBM i, apply the relevantPTFas instructed on the reference site.