Multiples vulnérabilités dans les produits IBM (04 septembre 2026)
Multiple vulnerabilities have been discovered in IBM products, including DB2 Query Management Facility and QRadar SIEM. These vulnerabilities can lead to data integrity compromise, denial-of-service attacks, and remote code execution. Affected products include various versions of DB2 and QRadar, with specific versions listed in the bulletin. Users are advised to refer to the linked IBM security bulletins for detailed information and to apply the necessary patches immediately.
Multiple vulnerabilities have been discovered within IBM products, presenting significant security risks. These vulnerabilities can be exploited to compromise data integrity, trigger denial-of-service attacks, and execute code remotely. Specifically, several versions of DB2 Query Management Facility and QRadar SIEM are affected.
What happened
IBM has identified a range of security flaws impacting its database and security monitoring products. These vulnerabilities allow attackers to potentially cause a denial-of-service attack, execute arbitrary code remotely, and compromise data integrity. The vulnerabilities are present in various versions of DB2 Query Management Facility and QRadar SIEM, with a detailed list of affected versions provided in the linked security bulletins. The vulnerabilities are related to improper input validation and insufficient access controls.
Technical details
The affected products include:
- DB2 Query Management Facility for z/OS versions 12.2.0.5 without the latest security patch.
- DB2 Query Management Facility for z/OS versions 13.1 without the latest security patch.
- DB2 Query Management Facility versions 13.1.1 without the latest security patch.
- DB2 Query Management Facility versions 13.1.2 without the latest security patch.
- DB2 Query Management Facility versions 13.1.3 without the latest security patch.
- QRadar SIEM versions 7.5.x prior to 7.5.0 UP16.
- QRadar SIEM versions 7.6.x prior to 7.6.0 FP 3.
- Sterling Connect:Direct for Microsoft Windows versions 6.3.x prior to 6.3.0.6_iFix076.
- Sterling Connect:Direct for Microsoft Windows versions 6.4.x prior to 6.4.0.5_iFix012.
The vulnerabilities are associated with CVE identifiers:
- CVE-2025-61984
- CVE-2025-61985
- CVE-2025-66614
- CVE-2025-68161
- CVE-2025-9714
- CVE-2026-16243
- CVE-2026-16439
- CVE-2026-16441
- CVE-2026-22007
- CVE-2026-22008
- CVE-2026-22013
- CVE-2026-22016
- CVE-2026-22018
- CVE-2026-22021
- CVE-2026-23865
- CVE-2026-24733
- CVE-2026-24734
- CVE-2026-34268
- CVE-2026-34282
- CVE-2026-34477
- CVE-2026-34478
- CVE-2026-34479
- CVE-2026-34480
- CVE-2026-34481
- CVE-2026-41254
- CVE-2026-46917
- CVE-2026-46968
- CVE-2026-47010
- CVE-2026-47021
- CVE-2026-47027
- CVE-2026-47057
- CVE-2026-47058
- CVE-2026-47059
- CVE-2026-47063
- CVE-2026-49844
- CVE-2026-55223
- CVE-2026-5588
- CVE-2026-60147
- CVE-2026-6918
- CVE-2026-8400
Impact
The exploitation of these vulnerabilities could lead to a denial-of-service attack, allowing an attacker to disrupt services. Successful remote code execution could enable attackers to gain full control over affected systems, potentially leading to data breaches and further system compromise. The vulnerabilities pose a significant risk to organizations relying on these IBM products for database management and security monitoring.
What to do
- Refer to the IBM security bulletins for detailed information and to obtain the latest patches: [https://www.ibm.com/support/pages/node/7285922](https://www.ibm.com/support/pages/node/7285922)
- [https://www.ibm.com/support/pages/node/7285923](https://www.ibm.com/support/pages/node/7285923)
- [https://www.ibm.com/support/pages/node/7286010](https://www.ibm.com/support/pages/node/7286010)
- [https://www.ibm.com/support/pages/node/7286012](https://www.ibm.com/support/pages/node/7286012)
- [https://www.ibm.com/support/pages/node/7286067](https://www.ibm.com/support/pages/node/7286067)
Why it matters
These vulnerabilities highlight the importance of timely patching and maintaining up-to-date security configurations. Organizations must prioritize addressing these flaws to mitigate the risk of exploitation and protect their sensitive data and systems. The widespread use of these IBM products means a successful attack could have a broad impact across various industries.