IBM disclosed several security issues affecting products across its portfolio, including IBM Cloud Databases for PostgreSQL, WebSphere Application Server, Liberty, IBM HTTP Server, and IBM Security Guardium. The referenced advisories indicate exposure to widely tracked vulnerabilities such as the OpenSSL certificate parsing flaws CVE-2022-3786 and CVE-2022-3602, alongside a Guardium command execution issue tracked as CVE-2023-35893.
The notices show IBM assessing and publishing product-specific impact information through support bulletins and X-Force Exchange reporting, with Guardium highlighted for command execution risk and other enterprise offerings reviewed for inherited third-party component exposure. The disclosures underscore the need for organizations using affected IBM platforms to verify product impact, review vendor bulletins, and apply available fixes or mitigations to reduce the risk of exploitation in database, application server, web server, and data security environments.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
IBM X-Force Exchange published a vulnerability report for IBM Security Guardium command execution flaw CVE-2023-35893. This marks a later technical reporting event for the vulnerability in IBM's exchange portal.
IBM published a support notice stating that IBM Cloud Databases for PostgreSQL was affected by a security vulnerability. The reference does not provide additional incident details beyond the disclosure.
IBM published support guidance on whether WebSphere Application Server, Liberty, and IBM HTTP Server were affected by the OpenSSL vulnerabilities CVE-2022-3786 and CVE-2022-3602.
IBM published a security bulletin/blog post addressing a potential CPU security issue. The reference indicates this disclosure occurred on the publication date of the bulletin.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
exchange.xforce.ibmcloud.com
Open sourceibm.com
Open sourceibm.com
Open sourceibm.com
Open sourceibm.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.