Description

IBM released security patches for over 100 vulnerabilities across various products. The biggest sufferers of these patches were Storage Defender, for which patches were issued for six critical vulnerabilities in third-party components for the Data Protect module. These can be exploited by attackers to cause denial-of-service attacks, memory corruption attacks, arbitrary file overwrite attacks, and application crashes. Another critical vulnerability, CVE-2025-48913, was fixed in a different manner in IBM Guardium Data Protection and relates to the usage of the Apache Tomcat server. A successful exploit allows remote code execution. IBM followed up with another critical bug fix related to a Django framework-associated SQL injection vulnerability within the Edge Data Collector. A different critical issue that involved the Maximo Application Suite in form-data library usage was also resolved. IBM Observability with Instana (OnPrem) - an IBM product- also had considerable updates with patches against dozens of vulnerabilities, some of which were critical in nature and included Tomcat, libxml2, and WebKit. Also, IBM remediated a critical vulnerability that existed within the Corosync library existing inside IBM Db2. The issue did pose threats associated with arbitrary code execution and process crashes based on some specific encryption settings. Apart from these pressing issues, IBM has also put out a flurry of patches relating to a range of critical and medium-risk vulnerabilities within its Content Collector, DataPower Operations Dashboard. To examine these patches more carefully, you can rely on the links given below within individual IBM security advisories.