IBM QRadar, WebSphere Patch Multiple Flaws
ANSSI advisory details multiple vulnerabilities in IBM QRadar App SDK and WebSphere products enabling DoS, data disclosure, and SSRF.
CERT-FR issued an advisory covering multiple vulnerabilities discovered in IBM products, including QRadar App SDK, WebSphere Application Server Liberty, WebSphere Hybrid Edition, and WebSphere Remote Server. The flaws span several vulnerability classes including remote denial of service, confidentiality breaches, server-side request forgery (SSRF), security policy bypass, and indirect remote code injection (XSS).
Affected versions include QRadar App SDK prior to 2.2.5, WebSphere Application Server Liberty prior to 26.0.0.8, WebSphere Hybrid Edition 5.1 without a set of listed security fixes, and WebSphere Remote Server 8.5.x prior to 8.5.5.31 and 9.x prior to 9.0.5.29. IBM has published a series of security bulletins detailing patches for the affected products, and organizations running these versions should apply the referenced fixes per IBM guidance. No active exploitation is indicated in the advisory; this is a routine patch notification covering numerous CVEs.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0865
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free