SB2026082422 - Multiple vulnerabilities in IBM Tivoli Monitoring
Published: August 24, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 4 vulnerabilities.
1) Security features bypass (CVE-ID: CVE-2026-5516)
CWE-ID: CWE-254 - Security Features
CVSSv4: 5.9 [CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote privileged attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. A remote privileged attacker can gain unauthorized access to sensitive information on the system.
2) Improper privilege management (CVE-ID: CVE-2026-3621)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 7.7 [CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to escalate privileges.
The vulnerability occurs when an application is deployed without authentication and authorization configured. A remote user can escalate privileges.
3) Resource exhaustion (CVE-ID: CVE-2026-9320)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
4) Inconsistent interpretation of HTTP requests (CVE-ID: CVE-2026-8646)
CWE-ID: CWE-444 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVSSv4: 9.1 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform HTTP request smuggling attacks.
The vulnerability exists due to improper validation of HTTP requests. A remote attacker can send a specially crafted HTTP request to the server and smuggle arbitrary HTTP headers.
Successful exploitation of vulnerability may allow an attacker to poison HTTP cache and perform phishing attacks.
Remediation
Install update from vendor's website.