SB2026100107 - Multiple vulnerabilities in IBM InfoSphere Optim Archive Viewer



SB2026100107 - Multiple vulnerabilities in IBM InfoSphere Optim Archive Viewer

Published: October 1, 2026 Updated: October 1, 2026

Security Bulletin ID SB2026100107
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 3
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 3 vulnerabilities.


1) Improper handling of highly compressed data (CVE-ID: CVE-2026-41608)

CWE-ID: CWE-409 - Improper Handling of Highly Compressed Data (Data Amplification)

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper handling of highly compressed data in Python THeaderTransport when processing compressed input. A remote attacker can send specially crafted compressed data to cause a denial of service.


2) Improper validation of certificate with host mismatch (CVE-ID: CVE-2026-66053)

CWE-ID: CWE-297 - Improper Validation of Certificate with Host Mismatch

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass hostname verification in TLS certificate validation.

The vulnerability exists due to improper validation of certificate with host mismatch in the Python TSSLSocket hostname matcher import in Apache Thrift Python bindings when establishing TLS connections. A remote attacker can present a certificate with a mismatched hostname to bypass hostname verification in TLS certificate validation.


3) Improper validation of certificate with host mismatch (CVE-ID: CVE-2026-41603)

CWE-ID: CWE-297 - Improper Validation of Certificate with Host Mismatch

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to impersonate a trusted host.

The vulnerability exists due to improper validation of certificate with host mismatch in Java TSSLTransportFactory when establishing TLS connections. A remote attacker can present a certificate with a mismatched hostname to impersonate a trusted host.


Remediation

Install update from vendor's website.