SB2026092314 - Multiple vulnerabilities in IBM Power Hardware Management Console
Published: September 23, 2026 Updated: September 30, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 vulnerabilities.
1) Incorrect Behavior Order: Validate Before Canonicalize (CVE-ID: CVE-2026-59083)
CWE-ID: CWE-180 - Incorrect Behavior Order: Validate Before Canonicalize
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass security controls.
The vulnerability exists due to incorrect URL decoding in RewriteValve when processing rewritten URIs. A remote attacker can send a specially crafted request to bypass security controls.
Only some configurations are vulnerable.
2) Improper access control (CVE-ID: CVE-2026-55956)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass security constraints.
The vulnerability exists due to improper access control in the default servlet when processing requests subject to configured security constraints with method or method omission settings. A remote attacker can send a crafted request using an ignored method to bypass security constraints.
Remediation
Install update from vendor's website.