Ibm I vulnerabilities
206 known vulnerabilities affecting ibm/i.
Total CVEs
206
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL21HIGH92MEDIUM87LOW6
Vulnerabilities
Page 11 of 11
CVE-2026-17438P4MEDIUMCVSS 4.4v7.3v7.4+2 more2026-08-13
CVE-2026-17438 [MEDIUM] CWE-269 CVE-2026-17438: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to obtain sensitive information or modify
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to obtain sensitive information or modify data due to improper privilege management.
nvd
CVE-2026-17071P4LOWCVSS 2.7v7.3v7.4+2 more2026-08-13
CVE-2026-17071 [LOW] CWE-22 CVE-2026-17071: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to perform file manipulatio
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to perform file manipulation due to path traversal.
nvd
CVE-2024-31870P4LOWCVSS 3.3v7.2v7.3+3 more2024-06-15
CVE-2024-31870 [LOW] CWE-204 CVE-2024-31870: IBM Db2 for i 7.2, 7.3, 7.4, and 7.5 supplies user defined table function is vulnerable to user enum
IBM Db2 for i 7.2, 7.3, 7.4, and 7.5 supplies user defined table function is vulnerable to user enumeration by a local authenticated attacker, without having authority to the related *USRPRF objects. This can be used by a malicious actor to gather information about users that can be targeted in further attacks. IBM X-Force ID: 287174.
nvd
CVE-2026-19086P4LOWCVSS 3.3v7.6v7.5+2 more2026-09-14
CVE-2026-19086 [LOW] CWE-125 CVE-2026-19086: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a denial of service as a result of a buffer overflow in a P
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a denial of service as a result of a buffer overflow in a PASE process. An authenticated attacker could leverage this to terminate their own process.
nvd
CVE-2020-4345P4LOWCVSS 3.3v7.2v7.3+1 more2020-05-17
CVE-2020-4345 [LOW] CWE-89 CVE-2020-4345: IBM i 7.2, 7.3, and 7.4 users running complex SQL statements under a specific set of circumstances m
IBM i 7.2, 7.3, and 7.4 users running complex SQL statements under a specific set of circumstances may allow a local user to obtain sensitive information that they should not have access to. IBM X-Force ID: 178318.
nvd
CVE-2024-35122P4LOWCVSS 2.8v7.2v7.3+2 more2025-01-24
CVE-2024-35122 [LOW] CWE-266 CVE-2024-35122: IBM i 7.2, 7.3, 7.4, and 7.5 is vulnerable to a file level local denial of service caused by an insu
IBM i 7.2, 7.3, 7.4, and 7.5 is vulnerable to a file level local denial of service caused by an insufficient authority requirement. A local non-privileged user can configure a referential constraint with the privileges of a user socially engineered to access the target file.
nvd
← Previous11 / 11