T

Threats

IBM Critical Vulnerabilities

Overview

IBM has disclosed five critical vulnerabilities across several software and infrastructure products. Four issues may be exploited remotely without authentication. The Langflow issue requires an attacker to reach a permitted run path that invokes the affected Python component, while the Tivoli-related WebSphere cross-site scripting issue requires user interaction.


Affected Versions

IBM Langflow OSS

IBM App Connect Enterprise

IBM webMethods Integration Server

  • Affected: On-premises versions 10.11 and 10.15 when the WmServiceMock package is present

  • Fixed: IBM states that no product patch or software update is required. Remove WmServiceMock from every production or internet-facing Integration Server node, then restart the server.

  • Source: IBM webMethods Integration WmServiceMock bulletin

IBM Power Hardware Management Console

IBM Tivoli System Automation Application Manager and WebSphere Application Server

  • Affected: Tivoli System Automation Application Manager 4.1 when shipped with WebSphere Application Server 8.5 or 9.0. The supporting WebSphere bulletin identifies affected traditional WebSphere ranges as 8.5.0.0 through 8.5.5.29 and 9.0.0.0 through 9.0.5.28.

  • Fixed: Apply the interim fix for APAR PH71757 at the minimum fix pack level required by IBM. Alternatively, apply WebSphere Fix Pack 8.5.5.30 or later, or 9.0.5.29 or later, when available for the relevant branch.

  • Source: IBM Tivoli System Automation Application Manager bulletin

  • Source: IBM WebSphere Application Server XSS bulletin


Vulnerability Breakdown

CVE-2026-13435 – Python Interpreter sandbox bypass

  • Severity: Critical

  • CVSS: 9.9

  • Description: Improper input validation in the Langflow OSS PythonREPL sandbox can allow supplied code to bypass validation. An attacker able to provide input to a deployed flow, agent or permitted run path that invokes the affected Python component may access sensitive server-process and in-memory values.

  • Impact: Exposure of provider API keys, database credentials and cryptographic key material. Under the default HS256 JWT configuration, exposed key material may enable token forgery for a known user identifier and decryption of stored credentials.

  • Conditions: Network access and low privileges are reflected in IBM’s CVSS vector. The affected Python component must be reachable through a deployed flow, agent or permitted run path.

CVE-2026-15435 – Path traversal and arbitrary file write

  • Severity: Critical

  • CVSS: 9.8

  • Description: IBM App Connect Enterprise does not adequately restrict pathnames. A remote attacker can send a specially crafted URL containing directory traversal sequences to write arbitrary files.

  • Impact: Compromise of confidentiality, integrity and availability through unauthorised file placement or modification.

  • Conditions: Network access is required. IBM’s CVSS vector indicates no privileges or user interaction are required.

CVE-2026-12118 – Deserialisation of untrusted data

  • Severity: Critical

  • CVSS: 9.8

  • Description: The WmServiceMock development and testing package bundled with IBM webMethods Integration Server can deserialize untrusted data. If the package is deployed on an exposed server, an unauthenticated remote attacker may execute arbitrary code.

  • Impact: Arbitrary code execution in the Integration Server environment, with potential system and data compromise.

  • Conditions: WmServiceMock must be installed and reachable. IBM states that it should not be deployed on production or internet-facing systems.

CVE-2026-12943 – OS command injection

  • Severity: Critical

  • CVSS: 9.8

  • Description: Improper validation of user-supplied input in IBM Power management systems can allow an unauthenticated attacker to execute arbitrary commands with elevated privileges.

  • Impact: Full compromise of confidentiality, integrity and availability on the affected management system.

  • Conditions: Network access is required. IBM’s CVSS vector indicates no privileges or user interaction are required.

CVE-2026-11707 – Administrative console login page cross-site scripting

  • Severity: Critical

  • CVSS: 9.3

  • Description: IBM WebSphere Application Server shipped with Tivoli System Automation Application Manager is vulnerable to cross-site scripting in the administrative console login page.

  • Impact: Execution of attacker-controlled script in a user’s browser, with high potential impact to confidentiality and integrity.

  • Conditions: The vulnerable administrative console must be reachable and a user must interact with malicious content. IBM’s CVSS vector indicates no privileges are required.


Mitigation

  • Upgrade Langflow OSS to version 1.10.2.

  • Upgrade IBM App Connect Enterprise 13.x to 13.0.8.0, or 12.x to 12.0.12.28.

  • Remove WmServiceMock from every production and internet-facing IBM webMethods Integration Server node, then restart Integration Server.

  • If WmServiceMock must remain in development or testing, isolate the environment and verify authentication is enforced on all Integration Server ports.

  • Apply the IBM Power HMC fixes for the affected architecture and branch.

  • Apply the WebSphere interim fix for APAR PH71757, or the applicable fixed WebSphere fix pack when available.

  • Prioritise internet-facing and management-plane systems, then confirm remediation through version and configuration checks.


Summary for IT Teams

  • Products: IBM App Connect Enterprise, IBM webMethods Integration Server, IBM Power HMC, IBM Langflow OSS, IBM Tivoli System Automation Application Manager and IBM WebSphere Application Server

  • Threat level: Critical, maximum CVSS 9.9

  • Action required: Identify affected versions, upgrade App Connect Enterprise and Langflow, remove WmServiceMock from production, apply Power HMC fixes and remediate WebSphere with APAR PH71757 or the applicable fixed fix pack.


Reference

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.