cbcvebase.

Ibm I vulnerabilities

68 known vulnerabilities affecting ibm/i.

Total CVEs
68
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH34MEDIUM27LOW3

Vulnerabilities

Page 2 of 4
CVE-2024-25050P3HIGHCVSS 7.8v7.2v7.3+3 more2024-04-28
CVE-2024-25050 [HIGH] CWE-427 CVE-2024-25050: IBM i 7.2, 7.3, 7.4, 7.5 and IBM Rational Development Studio for i 7.2, 7.3, 7.4, 7.5 networking and IBM i 7.2, 7.3, 7.4, 7.5 and IBM Rational Development Studio for i 7.2, 7.3, 7.4, 7.5 networking and compiler infrastructure could allow a local user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privileges. IBM X-Force ID: 283242.
nvd
CVE-2024-31890P3HIGHCVSS 7.8≥ 7.3, ≤ 7.5v7.3, 7.4, 7.52024-06-21
CVE-2024-31890 [HIGH] CWE-250 CVE-2024-31890: IBM i 7.3, 7.4, and 7.5 product IBM TCP/IP Connectivity Utilities for i contains a local privilege e IBM i 7.3, 7.4, and 7.5 product IBM TCP/IP Connectivity Utilities for i contains a local privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain root access to the host operating system. IBM X-Force ID: 288171.
nvd
CVE-2023-40685P3HIGHCVSS 7.8v7.2v7.3+3 more2023-10-29
CVE-2023-40685 [HIGH] CWE-269 CVE-2023-40685: Management Central as part of IBM i 7.2, 7.3, 7.4, and 7.5 Navigator contains a local privilege esca Management Central as part of IBM i 7.2, 7.3, 7.4, and 7.5 Navigator contains a local privilege escalation vulnerability. A malicious actor with command line access to the operating system can exploit this vulnerability to elevate privileges to gain root access to the operating system. IBM X-Force ID: 264116.
nvd
CVE-2013-5385P3HIGHCVSS 8.5v6.1v7.12014-01-02
CVE-2013-5385 [HIGH] CVE-2013-5385: The OSPF implementation in IBM i 6.1 and 7.1, in z/OS on zSeries servers, and in Networking Operatin The OSPF implementation in IBM i 6.1 and 7.1, in z/OS on zSeries servers, and in Networking Operating System (aka NOS, formerly BLADE Operating System) does not properly validate Link State Advertisement (LSA) type 1 packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtai
nvd
CVE-2024-22346P3HIGHCVSS 7.8v7.2v7.3+3 more2024-03-14
CVE-2024-22346 [HIGH] CWE-427 CVE-2024-22346: Db2 for IBM i 7.2, 7.3, 7.4, and 7.5 infrastructure could allow a local user to gain elevated privil Db2 for IBM i 7.2, 7.3, 7.4, and 7.5 infrastructure could allow a local user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privilege. IBM X-Force ID: 280203.
nvd
CVE-2023-30988P3HIGHCVSS 7.8v7.2v7.3+3 more2023-07-16
CVE-2023-30988 [HIGH] CWE-269 CVE-2023-30988: The IBM i 7.2, 7.3, 7.4, and 7.5 product Facsimile Support for i contains a local privilege escalati The IBM i 7.2, 7.3, 7.4, and 7.5 product Facsimile Support for i contains a local privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain root access to the host operating system. IBM X-Force ID: 254016.
nvd
CVE-2023-38721P3HIGHCVSS 7.8v7.2v7.3+3 more2023-08-14
CVE-2023-38721 [HIGH] CWE-269 CVE-2023-38721: The IBM i 7.2, 7.3, 7.4, and 7.5 product Facsimile Support for i contains a local privilege escalati The IBM i 7.2, 7.3, 7.4, and 7.5 product Facsimile Support for i contains a local privilege escalation vulnerability. A malicious actor could gain access to a command line with elevated privileges allowing root access to the host operating system. IBM X-Force ID: 262173.
nvd
CVE-2023-40375P3HIGHCVSS 7.8v7.2v7.3+3 more2023-09-28
CVE-2023-40375 [HIGH] CWE-269 CVE-2023-40375: Integrated application server for IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation Integrated application server for IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain root access to the host operating system. IBM X-Force ID: 263580.
nvd
CVE-2023-40686P3HIGHCVSS 7.8v7.2v7.3+3 more2023-10-29
CVE-2023-40686 [HIGH] CWE-269 CVE-2023-40686: Management Central as part of IBM i 7.2, 7.3, 7.4, and 7.5 Navigator contains a local privilege esca Management Central as part of IBM i 7.2, 7.3, 7.4, and 7.5 Navigator contains a local privilege escalation vulnerability. A malicious actor with command line access to the operating system can exploit this vulnerability to elevate privileges to gain component access to the operating system. IBM X-Force ID: 264114.
nvd
CVE-2023-40378P3HIGHCVSS 7.8v7.2v7.3+3 more2023-10-15
CVE-2023-40378 [HIGH] CWE-269 CVE-2023-40378: IBM Directory Server for IBM i contains a local privilege escalation vulnerability. A malicious act IBM Directory Server for IBM i contains a local privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain component access to the host operating system. IBM X-Force ID: 263584.
nvd
CVE-2024-27264P3HIGHCVSS 7.8v7.2v7.3+3 more2024-05-22
CVE-2024-27264 [HIGH] CWE-269 CVE-2024-27264: IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privile IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privilege. IBM X-Force ID: 284563.
nvd
CVE-2026-1376P3HIGHCVSS 7.5v7.62026-03-17
CVE-2026-1376 [HIGH] CWE-770 CVE-2026-1376: IBM i 7.6 could allow a remote attacker to cause a denial of service using failed authentication con IBM i 7.6 could allow a remote attacker to cause a denial of service using failed authentication connections due to improper allocation of resources.
nvd
CVE-2023-23470P3HIGHCVSS 7.2v7.2v7.3+3 more2023-05-04
CVE-2023-23470 [HIGH] CWE-89 CVE-2023-23470: IBM i 7.2, 7.3, 7.4, and 7.5 could allow an authenticated privileged administrator to gain elevated IBM i 7.2, 7.3, 7.4, and 7.5 could allow an authenticated privileged administrator to gain elevated privileges in non-default configurations, as a result of improper SQL processing. By using a specially crafted SQL operation, the administrator could exploit the vulnerability to perform additional administrator operations. IBM X-Force ID: 244510.
nvd
CVE-2023-30989P3HIGHCVSS 7.8v7.2v7.3+3 more2023-07-16
CVE-2023-30989 [HIGH] CWE-269 CVE-2023-30989: IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerabili IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain all object access to the host operating system. IBM X-Force ID: 254017.
nvd
CVE-2023-40377P3HIGHCVSS 7.8v7.2v7.3+2 more2023-10-16
CVE-2023-40377 [HIGH] CWE-269 CVE-2023-40377: Backup, Recovery, and Media Services (BRMS) for IBM i 7.2, 7.3, and 7.4 contains a local privilege e Backup, Recovery, and Media Services (BRMS) for IBM i 7.2, 7.3, and 7.4 contains a local privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain component access to the host operating system. IBM X-Force ID: 263583.
nvd
CVE-2026-10852P3HIGHCVSS 7.5v7.3v7.4+2 more2026-06-22
CVE-2026-10852 [HIGH] CWE-476 CVE-2026-10852: IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to deni IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to denial of service in the WebSphere WebServer Plug-in component when an attacker can pass crafted requests to the web server.
nvd
CVE-2024-38330P3HIGHCVSS 7.8v7.2v7.3+2 more2024-07-08
CVE-2024-38330 [HIGH] CWE-427 CVE-2024-38330: IBM System Management for i 7.2, 7.3, and 7.4 could allow a local user to gain elevated privileges d IBM System Management for i 7.2, 7.3, and 7.4 could allow a local user to gain elevated privileges due to an unqualified library program call. A malicious actor could cause user-controlled code to run with administrator privilege. IBM X-Force ID: 295227.
nvd
CVE-2024-27275P3HIGHCVSS 7.8v7.2v7.3+2 more2024-06-15
CVE-2024-27275 [HIGH] CWE-266 CVE-2024-27275: IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability caused by an insuff IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability caused by an insufficient authority requirement. A local user without administrator privilege can configure a physical file trigger to execute with the privileges of a user socially engineered to access the target file. The correction is to require administrator privilege
nvd
CVE-2024-47104P3MEDIUMCVSS 6.8v7.4v7.5+1 more2024-12-18
CVE-2024-47104 [MEDIUM] CWE-732 CVE-2024-47104: IBM i 7.4 and 7.5 is vulnerable to an authenticated user gaining elevated privilege to a physical fi IBM i 7.4 and 7.5 is vulnerable to an authenticated user gaining elevated privilege to a physical file. A user with authority to a view can alter the based-on physical file security attributes without having object management rights to the physical file. A malicious actor can use the elevated privileges to perform actions restricted by their view pr
nvd
CVE-2025-36371P3MEDIUMCVSS 6.5v7.2v7.3+3 more2025-11-19
CVE-2025-36371 [MEDIUM] CWE-598 CVE-2025-36371: IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 are impacted by obtaining an information vulnerability in the data IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 are impacted by obtaining an information vulnerability in the database plan cache implementation. A user with access to the database plan cache could see information they do not have authority to view.
nvd
Ibm I vulnerabilities | cvebase