Junglewise Threat Intelligence

CVE-2026-3676: IBM Cloud APM and Db2 denial of service in Fenced environment

CVE-2026-3676 · Severity: medium · CVSS 6.5 · Published 2026-05-27

Executive brief

IBM Cloud Application Performance Management (APM) is vulnerable to a denial of service due to an underlying issue in its bundled database component, IBM Db2. An authenticated user could exploit this flaw to crash the database service or make it unresponsive. This would disrupt the monitoring and management capabilities of the APM platform, potentially leading to operational blind spots during an outage.

Technical details

A denial of service vulnerability exists in the IBM Db2 component bundled with IBM Cloud APM. The flaw is classified as CWE-1284 (Improper Validation of Specified Quantity in Input) and resides within the data query logic of the Db2 Fenced environment. An authenticated attacker with network access can submit specially crafted SQL queries that fail to be properly neutralized, leading to a system crash or resource exhaustion. The vulnerability affects Db2 versions 11.5 and 12.1. Remediation requires updating the underlying Db2 server and applying the 8.1.4.0-IBM-APM-SERVER-IF0004 (or later) patch to the Cloud APM server.

Affected products

  • IBM Cloud APM Base Private 8.1.4
  • IBM Cloud APM Advanced Private 8.1.4
  • IBM Db2 for Linux, UNIX and Windows 11.5.0 through 11.5.9, 12.1.0 through 12.1.4

Timeline

  • 2026-05-27: advisory: Initial NVD publication and IBM security bulletin release.

References

Related threats