cbcvebase.

Ibm I vulnerabilities

206 known vulnerabilities affecting ibm/i.

Total CVEs
206
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL21HIGH92MEDIUM87LOW6

Vulnerabilities

Page 1 of 11
CVE-2026-18847P2CRITICALCVSS 9.8v7.3v7.4+2 more2026-08-12
CVE-2026-18847 [CRITICAL] CWE-346 CVE-2026-18847: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to harvest credentials du IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to harvest credentials due to spoofing of Navigator for i.
nvd
CVE-2026-18221P2CRITICALCVSS 9.8v7.3v7.4+2 more2026-09-04
CVE-2026-18221 [CRITICAL] CWE-287 CVE-2026-18221: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized access due to improp IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized access due to improper validation of client-supplied authentication parameters.
nvd
CVE-2026-16860P2CRITICALCVSS 9.9≥ 7.3, ≤ 7.6v7.6+3 more2026-08-12
CVE-2026-16860 [CRITICAL] CWE-427 CVE-2026-16860: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code d IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an uncontrolled search path element.
nvd
CVE-2026-16906P2HIGHCVSS 8.8v7.5v7.62026-08-12
CVE-2026-16906 [HIGH] CWE-78 CVE-2026-16906: IBM i 7.6, and 7.5 could allow a remote authenticated attacker to execute arbitrary commands with el IBM i 7.6, and 7.5 could allow a remote authenticated attacker to execute arbitrary commands with elevated privileges due to improper neutralization of special elements used in an OS command.
nvd
CVE-2026-17642P2HIGHCVSS 8.8v7.3v7.4+2 more2026-08-12
CVE-2026-17642 [HIGH] CWE-78 CVE-2026-17642: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary comman IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
nvd
CVE-2026-17218P2CRITICALCVSS 9.8≥ 7.3, ≤ 7.6v7.6+3 more2026-08-12
CVE-2026-17218 [CRITICAL] CWE-787 CVE-2026-17218: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to an out-o IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.
nvd
CVE-2026-17417P2HIGHCVSS 8.8v7.3v7.4+2 more2026-08-12
CVE-2026-17417 [HIGH] CWE-78 CVE-2026-17417: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary comman IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of shell metacharacters.
nvd
CVE-2026-18193P2CRITICALCVSS 10.0v7.3v7.4+2 more2026-08-13
CVE-2026-18193 [CRITICAL] CWE-269 CVE-2026-18193: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to im IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of user-controlled addresses.
nvd
CVE-2026-17276P2CRITICALCVSS 9.9≥ 7.3, ≤ 7.6v7.6+3 more2026-08-12
CVE-2026-17276 [CRITICAL] CWE-269 CVE-2026-17276: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to escalate privileges due IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to escalate privileges due to improper authorization in the handling of high-authority threads.
nvd
CVE-2026-16674P2HIGHCVSS 8.8v7.3v7.4+2 more2026-08-13
CVE-2026-16674 [HIGH] CWE-426 CVE-2026-16674: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code d IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an untrusted search path.
nvd
CVE-2026-17083P2CRITICALCVSS 9.8v7.3v7.4+2 more2026-08-12
CVE-2026-17083 [CRITICAL] CWE-787 CVE-2026-17083: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a stack- IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.
nvd
CVE-2026-18249P2CRITICALCVSS 9.9v7.3v7.4+2 more2026-08-13
CVE-2026-18249 [CRITICAL] CWE-269 CVE-2026-18249: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improper validation of pointers read from Java-controlled addresses.
nvd
CVE-2026-16961P2CRITICALCVSS 9.8v7.4v7.5+1 more2026-08-13
CVE-2026-16961 [CRITICAL] CWE-89 CVE-2026-16961: IBM i 7.6, 7.5, and 7.4 s vulnerable to SQL injection. A remote attacker could send specially crafte IBM i 7.6, 7.5, and 7.4 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
nvd
CVE-2026-17111P2CRITICALCVSS 9.8v7.3v7.4+2 more2026-08-12
CVE-2026-17111 [CRITICAL] CWE-89 CVE-2026-17111: IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A remote attacker could send specially c IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
nvd
CVE-2026-18669P2HIGHCVSS 8.8≥ 7.3, ≤ 7.6v7.6+3 more2026-08-12
CVE-2026-18669 [HIGH] CWE-250 CVE-2026-18669: IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to a privilege escalation as the result of a remote code IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to a privilege escalation as the result of a remote code execution vulnerability in the activation engine component. An authenticated attacker can execute a maliciously planted script with root authority.
nvd
CVE-2026-18683P2HIGHCVSS 8.8v7.3v7.4+2 more2026-08-12
CVE-2026-18683 [HIGH] CWE-78 CVE-2026-18683: IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to privilege escalation via Navigator for i. An authentic IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to privilege escalation via Navigator for i. An authenticated user could elevate privileges to a root user to execute commands.
nvd
CVE-2026-16908P2HIGHCVSS 8.8v7.3v7.4+2 more2026-08-13
CVE-2026-16908 [HIGH] CWE-22 CVE-2026-16908: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized access IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized access to arbitrary objects due to a path traversal vulnerability.
nvd
CVE-2026-18713P2HIGHCVSS 8.8≥ 7.2, ≤ 7.6v7.6+3 more2026-08-12
CVE-2026-18713 [HIGH] CWE-269 CVE-2026-18713: IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to privilege escalation via Navigator for i. An authentica IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to privilege escalation via Navigator for i. An authenticated user could elevate privileges to a root user to execute commands.
nvd
CVE-2026-16867P2CRITICALCVSS 9.8v7.3v7.4+2 more2026-08-13
CVE-2026-16867 [CRITICAL] CWE-287 CVE-2026-16867: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server resources with the privi IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server resources with the privileges of an authenticated user due to improper authentication during NTLM session negotiation.
nvd
CVE-2026-17197P2CRITICALCVSS 9.8v7.3v7.4+2 more2026-08-13
CVE-2026-17197 [CRITICAL] CWE-287 CVE-2026-17197: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to im IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of client-asserted identity.
nvd
1 / 11Next →