Resource exhaustion in IBM WebSphere Application Server Liberty - CVE-2026-4410
Published: May 21, 2026
Vulnerability identifier: #VU132041
CSH Severity: Low
CVSS v4: 5.9 [CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-4410
CWE-ID: CWE-400
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows an adjacent user to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources. An adjacent user can trigger resource exhaustion and perform a denial of service (DoS) attack by sending a specially-crafted request.
Affected software
IBM WebSphere Application Server Liberty
IBM Tivoli Application Dependency Discovery Manager
Enterprise Application Runtimes
PowerVM NovaLink
Cloud Pak for Applications
WebSphere Hybrid Edition
Storage Protect for Virtual Environments: Data Protection for VMware
Storage Protect for Virtual Environments: Data Protection for Hyper-V
Storage Protect Operations Center
IBM Tivoli Monitoring
IBM TXSeries for Multiplatforms
IBM SPSS Collaboration and Deployment Services
IBM Tivoli Application Dependency Discovery Manager
Enterprise Application Runtimes
PowerVM NovaLink
Cloud Pak for Applications
WebSphere Hybrid Edition
Storage Protect for Virtual Environments: Data Protection for VMware
Storage Protect for Virtual Environments: Data Protection for Hyper-V
Storage Protect Operations Center
IBM Tivoli Monitoring
IBM TXSeries for Multiplatforms
IBM SPSS Collaboration and Deployment Services
How to mitigate CVE-2026-4410
Install updates from vendor's website.
IBM WebSphere Application Server Liberty - update to 26.0.0.6
PowerVM NovaLink - addressed in versions 2.2.1.1-260708, 2.3.3-260714
IBM Tivoli Monitoring - update to 6.3.0.7 Service Pack 5
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.2.2.0
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.2.2.0
IBM TXSeries for Multiplatforms - update to 11.1.0.0 ifix22
Storage Protect Operations Center - update to 8.2.2
PowerVM NovaLink - addressed in versions 2.2.1.1-260708, 2.3.3-260714
IBM Tivoli Monitoring - update to 6.3.0.7 Service Pack 5
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.2.2.0
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.2.2.0
IBM TXSeries for Multiplatforms - update to 11.1.0.0 ifix22
Storage Protect Operations Center - update to 8.2.2
External References
Related Security Bulletins
- Resource exhaustion in IBM WebSphere Application Server - Liberty
- Resource exhaustion in IBM WebSphere Hybrid Edition
- Resource exhaustion in IBM Enterprise Application Runtimes
- Resource exhaustion in IBM Cloud Pak for Applications
- Multiple vulnerabilities in IBM SPSS Collaboration and Deployment Services
- Multiple vulnerabilities in IBM Tivoli Monitoring
- Multiple vulnerabilities in IBM PowerVM Novalink
- Multiple vulnerabilities in IBM TXSeries for Multiplatforms
- Resource exhaustion in IBM Storage Protect Operations Center
- Resource exhaustion in IBM Storage Protect Data Protection for Virtual Environments
- Multiple vulnerabilities in IBM Tivoli Application Dependency Discovery Manager