IBM Cloud APM, Base Private 8.1.4 and IBM Cloud APM, Advanced Private 8.1.4 IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in the data query logic of the Fenced environment.

Project Subscriptions

Vendors Products
Cloud Apm Advanced Private Subscribe
Cloud Apm Base Private Subscribe
Advisories

No advisories yet.

Fixes

Solution

The vulnerabilities can be remediated by first applying the necessary fixes to your DB2 V11.5 server. The fixes can be accessed from the following security bulletins: Security Bulletin: https://www.ibm.com/support/fixcentral/swg/selectFixes?product=ibm%2FTivoli%2FIBM+Application+Performance+Management&fixids=8.1.4.0-IBM-APM-SERVER-IF0019&source=SAR&function=fixId&parent=IBM%20Performance%20Management%20family


Workaround

No workaround given by the vendor.

History

Wed, 27 May 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 27 May 2026 14:15:00 +0000

Type Values Removed Values Added
Description IBM Cloud APM, Base Private 8.1.4 and IBM Cloud APM, Advanced Private 8.1.4 IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in the data query logic of the Fenced environment.
Title There are multiple vulnerabilities in IBM DB2 bundled with IBM Application Performance Management products.
First Time appeared Ibm
Ibm cloud Apm Advanced Private
Ibm cloud Apm Base Private
Weaknesses CWE-1284
CPEs cpe:2.3:a:ibm:cloud_apm_advanced_private:8.1.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_apm_base_private:8.1.4:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm cloud Apm Advanced Private
Ibm cloud Apm Base Private
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-05-27T14:38:08.383Z

Reserved: 2026-03-06T21:17:59.734Z

Link: CVE-2026-3676

cve-icon Vulnrichment

Updated: 2026-05-27T14:37:34.558Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-05-27T14:16:47.123

Modified: 2026-05-27T14:53:51.833

Link: CVE-2026-3676

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-27T17:45:32Z

Weaknesses