Incorrect Calculation of Buffer Size in omr - CVE-2026-1188
Published: February 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to API function to return the textual names of all supported processor features was not accounting for the separator inserted between processor features. A remote attacker can pass specially crafted data to the application, trigger the incorrect calculation of buffer size and execute arbitrary code on the target system.
Affected software
SOAR App Host
DataStage on Cloud Pak for Data
Communications Server for Linux
InfoSphere Data Architect
IBM OpenPages with Watson
CICS Transaction Gateway Desktop Edition
CICS Transaction Gateway for Multiplatforms
DevOps Code ClearCase
IBM Sterling Connect:Direct for Microsoft Windows
Storage Protect for Virtual Environments: Data Protection for Hyper-V
Storage Protect for Space Management
Storage Protect for Virtual Environments: Data Protection for VMware
Storage Protect Client
Host On-Demand
Robotic Process Automation for Cloud Pak
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
Legacy Module
SUSE Package Hub 15
IBM Sterling Connect:Direct FTP+
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Sterling Partner Engagement Manager
IBM Sterling Control Center
Communications Server for Linux on System z
Communications Server for Data Center Deployment
IBM Tivoli Netcool Impact
IBM Rational Build Forge
IBM Tivoli Netcool/OMNIbus WebGUI
IBM TXSeries for Multiplatforms
IBM SPSS Collaboration and Deployment Services
WebSphere eXtreme Scale
IBM Common Licensing
IBM Rational ClearCase
IBM Transformation Extender Advanced
IBM Security Verify Governance
IBM SPSS Modeler
IBM Sterling Connect:Direct for UNIX
Tivoli Composite Application Manager for Transactions
IBM MQ
IBM Power Hardware Management Console (HMC)
SPSS Statistics
IBM Sterling Connect:Direct File Agent
IBM Data Studio Client
IBM DataPower Gateway
IBM Enterprise Content Management System Monitor
Planning Analytics Local
IBM Tivoli Application Dependency Discovery Manager
IBM License Metric Tool
IBM Cognos Command Center
Rational Business Developer (RBD)
IBM CICS TX Standard
IBM App Connect Enterprise
IBM CICS TX Advanced
IBM DB2
IBM Security SOAR
java-1_8_0-ibm-alsa
java-1_8_0-ibm-plugin
java-1_8_0-ibm-devel
java-1_8_0-ibm
java-1_8_0-ibm-demo
java-1_8_0-ibm-src
java-1_8_0-openj9-demo
java-1_8_0-openj9-demo-debuginfo
java-1_8_0-openj9-debugsource
java-1_8_0-openj9-src
java-1_8_0-openj9-devel
java-1_8_0-openj9-devel-debuginfo
java-1_8_0-openj9-debuginfo
java-1_8_0-openj9-accessibility
java-1_8_0-openj9-headless-debuginfo
java-1_8_0-openj9
java-1_8_0-openj9-headless
Informix Dynamic Server
How to mitigate CVE-2026-1188
IBM Sterling Connect:Direct FTP+ - update to 1.3.0.4
IBM Sterling Connect:Direct File Agent - update to 1.4.0.5 iFix006
SOAR App Host - update to 1.15.7.0
Planning Analytics Local - update to 2.1.19
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.3.1
DataStage on Cloud Pak for Data - update to 5.3.1 patch 3
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.6, 6.2.4.4
IBM Sterling Control Center - addressed in versions 6.3.1.0.7, 6.4.1.0.1, 6.4.2.0.1
IBM Tivoli Netcool Impact - update to 7.1.0.38
IBM Rational Build Forge - update to 8.0.0.30
IBM TXSeries for Multiplatforms - update to 11.1.0.0 ifix16
WebSphere eXtreme Scale - update to 8.6.1.6 PH70422
InfoSphere Data Architect - update to 9.2.1
IBM License Metric Tool - update to 9.2.42
Rational Business Developer (RBD) - addressed in versions 9.6.1.1, 9.7.1
IBM Transformation Extender Advanced - addressed in versions 10.0.1.11 1iFix, 10.0.2.1 1iFix
IBM Security Verify Governance - update to 10.0.2.0.7
IBM Cognos Command Center - update to 10.2.5 FP1 IF3
IBM DataPower Gateway - addressed in versions 10.5.0.21, 10.6.0.9, 11.0.0.0
IBM CICS TX Standard - update to 11.1.0.0 ifix39
IBM App Connect Enterprise - addressed in versions 12.0.12.23, 13.0.6.2
IBM Security SOAR - update to 51.0.9.0
java-1_8_0-ibm-alsa - addressed in versions 1.8.0_sr8.65-30.150.1, 1.8.0_sr8.65-150000.3.116.1
java-1_8_0-ibm-plugin - addressed in versions 1.8.0_sr8.65-30.150.1, 1.8.0_sr8.65-150000.3.116.1
java-1_8_0-ibm-devel - addressed in versions 1.8.0_sr8.65-30.150.1, 1.8.0_sr8.65-150000.3.116.1
java-1_8_0-ibm - addressed in versions 1.8.0_sr8.65-30.150.1, 1.8.0_sr8.65-150000.3.116.1
java-1_8_0-ibm-demo - update to 1.8.0_sr8.65-150000.3.116.1
java-1_8_0-ibm-src - update to 1.8.0_sr8.65-150000.3.116.1
java-1_8_0-openj9-demo - update to 1.8.0.492-150200.3.68.1
java-1_8_0-openj9-demo-debuginfo - update to 1.8.0.492-150200.3.68.1
java-1_8_0-openj9-debugsource - update to 1.8.0.492-150200.3.68.1
java-1_8_0-openj9-src - update to 1.8.0.492-150200.3.68.1
java-1_8_0-openj9-devel - update to 1.8.0.492-150200.3.68.1
java-1_8_0-openj9-devel-debuginfo - update to 1.8.0.492-150200.3.68.1
java-1_8_0-openj9-debuginfo - update to 1.8.0.492-150200.3.68.1
java-1_8_0-openj9-accessibility - update to 1.8.0.492-150200.3.68.1
java-1_8_0-openj9-headless-debuginfo - update to 1.8.0.492-150200.3.68.1
java-1_8_0-openj9 - update to 1.8.0.492-150200.3.68.1
java-1_8_0-openj9-headless - update to 1.8.0.492-150200.3.68.1
IBM Enterprise Content Management System Monitor - update to 5.7.000 FP2
IBM Sterling Connect:Direct for UNIX - addressed in versions 6.3.0.6.iFix033, 6.4.0.4.iFix017
IBM Sterling Connect:Direct for Microsoft Windows - addressed in versions 6.3.0.6.39, 6.4.0.4.10
Tivoli Composite Application Manager for Transactions - update to 7.4.0.2.27
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.2.1
Storage Protect for Space Management - update to 8.2.1
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.2.1
Storage Protect Client - update to 8.2.1
IBM MQ - addressed in versions 9.1.0.36, 9.2.0.42, 9.3.0.40, 9.4.5.1
IBM CICS TX Advanced - update to 10.1.0.0 ifix46
IBM Power Hardware Management Console (HMC) - addressed in versions 10.3.1063.2, 11.1.1111.5
Informix Dynamic Server - update to 12.10.xC16W6
Host On-Demand - addressed in versions 15.0.4 iFix001, 16.0.2
Robotic Process Automation for Cloud Pak - addressed in versions 23.0.20.6, 30.0.2
SPSS Statistics - addressed in versions 28.0.1.1 IF017, 29.0.2.0 IF018, 30.0.0.0 IF014, 31.0.2.0 IF06
External References
Related Security Bulletins
- Incorrect calculation of buffer size in Eclipse OMR
- Multiple vulnerabilities in IBM App Connect Enterprise
- Multiple vulnerabilities in IBM SPSS Collaboration and Deployment Services
- Multiple vulnerabilities in IBM CICS TX Standard
- Multiple vulnerabilities in IBM TXSeries for Multiplatforms
- Multiple vulnerabilities in IBM Security Verify Governance
- Multiple vulnerabilities in IBM CICS TX Advanced
- Multiple vulnerabilities in IBM Cognos Command Center
- IBM License Metric Tool update for Eclipse OMR
- IBM Watson Speech Services Cartridge update for Eclipse OMR
- Multiple vulnerabilities in IBM Tivoli Netcool/OMNIbus_GUI
- Multiple vulnerabilities in IBM Sterling Connect:Direct for Microsoft Windows
- Multiple vulnerabilities in IBM Sterling Connect:Direct File Agent
- IBM Security SOAR update for Eclipse OMR
- Multiple vulnerabilities in IBM CICS Transaction Gateway for Multiplatforms and CICS Transaction Gateway Desktop Edition
- IBM OpenPages update for Eclipse OMR
- Multiple vulnerabilities in IBM Informix Dynamic Server
- Multiple vulnerabilities in IBM Control Center
- Multiple vulnerabilities in IBM Transformation Extender Advanced
- Multiple vulnerabilities in IBM Sterling Connect:Direct for UNIX
- Multiple vulnerabilities in IBM Sterling Connect:Direct FTP+
- IBM Communications Server (CS) for Data Center Deployment, CS for Linux, and CS for Linux on System z update for Eclipse OMR
- Multiple vulnerabilities in IBM SPSS Modeler
- IBM SOAR App Host update for Eclipse OMR
- Multiple vulnerabilities in IBM WebSphere Extreme Scale
- IBM Common Licensing update for Eclipse OMR
- Multiple vulnerabilities in IBM Storage Protect Backup-Archive Client, IBM Storage Protect for Virtual Environments and IBM Storage Protect for Space Management
- Multiple vulnerabilities in IBM Rational Build Forge
- Multiple vulnerabilities in IBM Power Hardware Management Console (HMC)
- Multiple vulnerabilities in IBM Db2
- Multiple vulnerabilities in IBM Tivoli Netcool Impact
- Multiple vulnerabilities in IBM DataPower Gateway
- Multiple vulnerabilities in IBM Planning Analytics Local
- IBM Tivoli Composite Application Manager for Transactions (Response Time) update for Eclipse OMR
- Multiple vulnerabilities in IBM Enterprise Content Management System Monitor
- Multiple vulnerabilities in IBM InfoSphere Data Architect
- Multiple vulnerabilities in IBM SPSS Statistics Client and Server
- Multiple vulnerabilities in IBM MQ
- Incorrect calculation of buffer size in IBM DevOps Code ClearCase
- IBM Rational Business Developer update for Eclipse OMR
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Multiple vulnerabilities in IBM Data Studio client
- SUSE update for java-1_8_0-openj9
- SUSE update for java-1_8_0-ibm
- IBM Tivoli Application Dependency Discovery Manager update for Eclipse OMR
- Multiple vulnerabilities in IBM DataStage on Cloud Pak for Data
- IBM Host On-Demand update for Eclipse OMR port library
- SUSE update for java-1_8_0-ibm
- Multiple vulnerabilities in IBM Sterling Partner Engagement Manager