Ibm I vulnerabilities
206 known vulnerabilities affecting ibm/i.
Total CVEs
206
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL21HIGH92MEDIUM87LOW6
Vulnerabilities
Page 10 of 11
CVE-2026-16941P4MEDIUMCVSS 4.3v7.4v7.5+1 more2026-09-04
CVE-2026-16941 [MEDIUM] CWE-863 CVE-2026-16941: IBM i 7.6, 7.5, and 7.4 could allow a remote authenticated attacker to modify certain system message
IBM i 7.6, 7.5, and 7.4 could allow a remote authenticated attacker to modify certain system messages due to improper authorization.
nvd
CVE-2023-42006P4MEDIUMCVSS 5.5v7.2v7.3+3 more2023-12-01
CVE-2023-42006 [MEDIUM] CWE-863 CVE-2023-42006: IBM Administration Runtime Expert for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to obtain se
IBM Administration Runtime Expert for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to obtain sensitive information caused by improper authority checks. IBM X-Force ID: 265266.
nvd
CVE-2026-17262P4MEDIUMCVSS 5.4v7.6v7.5+2 more2026-09-18
CVE-2026-17262 [MEDIUM] CWE-78 CVE-2026-17262: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to improp
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to improper validation of FTP authentication commands.
nvd
CVE-2023-47741P4MEDIUMCVSS 5.3v7.3v7.4+2 more2023-12-18
CVE-2023-47741 [MEDIUM] CWE-522 CVE-2023-47741: IBM i 7.3, 7.4, 7.5, IBM i Db2 Mirror for i 7.4 and 7.5 web browser clients may leave clear-text pa
IBM i 7.3, 7.4, 7.5, IBM i Db2 Mirror for i 7.4 and 7.5 web browser clients may leave clear-text passwords in browser memory that can be viewed using common browser tools before the memory is garbage collected. A malicious actor with access to the victim's PC could exploit this vulnerability to gain access to the IBM i operating system. IBM X-Force I
nvd
CVE-2022-43857P4MEDIUMCVSS 4.3v7.3v7.4+1 more2022-12-22
CVE-2022-43857 [MEDIUM] CWE-22 CVE-2022-43857: IBM Navigator for i 7.3, 7.4 and 7.5 could allow an authenticated user to access IBM Navigator for i
IBM Navigator for i 7.3, 7.4 and 7.5 could allow an authenticated user to access IBM Navigator for i log files they are authorized to but not while using this interface. The remote authenticated user can bypass the interface checks and download log files by modifying servlet filter. IBM X-Force ID: 239301.
nvd
CVE-2022-43859P4MEDIUMCVSS 4.3v7.3v7.4+1 more2022-12-22
CVE-2022-43859 [MEDIUM] CWE-89 CVE-2022-43859: IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive informat
IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information for an object they are authorized to but not while using this interface. By performing a UNION based SQL injection an attacker could see file permissions through this interface. IBM X-Force ID: 239304.
nvd
CVE-2026-17088P4MEDIUMCVSS 4.3v7.3v7.4+2 more2026-08-13
CVE-2026-17088 [MEDIUM] CWE-22 CVE-2026-17088: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive informa
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a path traversal vulnerability.
nvd
CVE-2026-18106P4MEDIUMCVSS 4.3v7.3v7.4+2 more2026-08-12
CVE-2026-18106 [MEDIUM] CWE-22 CVE-2026-18106: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive informa
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of user-supplied path input.
nvd
CVE-2026-18068P4MEDIUMCVSS 4.3v7.3v7.4+2 more2026-08-13
CVE-2026-18068 [MEDIUM] CWE-200 CVE-2026-18068: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to a
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to a byte-count and element-count confusion.
nvd
CVE-2026-16871P4MEDIUMCVSS 4.3v7.3v7.4+2 more2026-08-13
CVE-2026-16871 [MEDIUM] CWE-787 CVE-2026-16871: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive informa
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a heap buffer overflow.
nvd
CVE-2026-18102P4MEDIUMCVSS 4.3v7.3v7.4+2 more2026-08-19
CVE-2026-18102 [MEDIUM] CWE-122 CVE-2026-18102: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to overwrite adjacent memor
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to overwrite adjacent memory due to an integer underflow during bounds checking.
nvd
CVE-2026-17043P4LOWCVSS 3.8≥ 7.3, ≤ 7.6v7.6+3 more2026-08-13
CVE-2026-17043 [LOW] CWE-22 CVE-2026-17043: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to delete arbitrary files d
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to delete arbitrary files due to path traversal.
nvd
CVE-2026-19280P4MEDIUMCVSS 5.2v7.6v7.5+2 more2026-09-14
CVE-2026-19280 [MEDIUM] CWE-787 CVE-2026-19280: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a denial of service as a result of a buffer overflow in a P
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a denial of service as a result of a buffer overflow in a PASE process. An authenticated attacker could leverage this to terminate their own process.
nvd
CVE-2026-16896P4MEDIUMCVSS 4.7v7.3v7.4+2 more2026-08-13
CVE-2026-16896 [MEDIUM] CWE-367 CVE-2026-16896: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to obtain unauthorized acces
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to obtain unauthorized access to files due to a time-of-check time-of-use (TOCTOU) race condition.
nvd
CVE-2022-43858P4MEDIUMCVSS 4.3v7.3v7.4+1 more2022-12-22
CVE-2022-43858 [MEDIUM] CWE-22 CVE-2022-43858: IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to access the file system an
IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to access the file system and download files they are authorized to but not while using this interface. The remote authenticated user can bypass the interface checks by modifying a parameter thereby gaining access to their files through this interface. IBM X-Force ID: 239303.
nvd
CVE-2026-18073P4MEDIUMCVSS 4.4v7.3v7.4+2 more2026-09-04
CVE-2026-18073 [MEDIUM] CWE-78 CVE-2026-18073: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to inject parameters into a
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to inject parameters into a CL command due to improper neutralization of special elements.
nvd
CVE-2024-55897P4MEDIUMCVSS 4.3v7.4, 7.52025-01-03
CVE-2024-55897 [MEDIUM] CWE-614 CVE-2024-55897: IBM PowerHA SystemMirror for i 7.4 and 7.5 does not set the secure attribute on authorization toke
IBM PowerHA SystemMirror for i 7.4 and 7.5
does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value
nvd
CVE-2026-18151P4MEDIUMCVSS 4.2v7.6v7.5+2 more2026-09-14
CVE-2026-18151 [MEDIUM] CWE-362 CVE-2026-18151: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive informa
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a race condition during the WebSocket handshake process.
nvd
CVE-2026-17469P4MEDIUMCVSS 5.5v7.3v7.4+2 more2026-09-04
CVE-2026-17469 [MEDIUM] CWE-787 CVE-2026-17469: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to an off-by-one write in the LPD queue name parser.
nvd
CVE-2026-18251P4MEDIUMCVSS 4.3v7.6v7.5+2 more2026-09-14
CVE-2026-18251 [MEDIUM] CWE-1385 CVE-2026-18251: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to im
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to improper validation of the WebSocket origin.
nvd