Security Advisory

IBM i and Java: multiple IBM Java SDK and Runtime vulnerabilities

Medium Last verified

What Happened

IBM published a security bulletin covering six CVEs (CVE-2026-22016, CVE-2026-22021, CVE-2026-22013, CVE-2026-22018, CVE-2026-34268, CVE-2026-22007) affecting the IBM Java SDK and IBM Java Runtime as shipped on IBM i.

Why It Matters

IBM Java underpins a wide range of IBM i middleware and third-party applications. Because Java versions are frequently pinned to specific application requirements, these fixes are easy to miss if version tracking is not centralized.

Recommended Actions

  • Inventory every installed Java version across LPARs, including versions pinned for specific applications
  • Apply IBM's release-specific PTFs per the bulletin's affected-product table
  • Coordinate with application owners before upgrading shared Java runtimes to avoid compatibility breaks

Sources