Ibm I vulnerabilities
206 known vulnerabilities affecting ibm/i.
Total CVEs
206
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL21HIGH92MEDIUM87LOW6
Vulnerabilities
Page 2 of 11
CVE-2022-22495P3HIGHCVSS 8.8v7.3v7.4+1 more2022-05-24
CVE-2022-22495 [HIGH] CWE-89 CVE-2022-22495: IBM i 7.3, 7.4, and 7.5 is vulnerable to SQL injection. A remote attacker could send specially craft
IBM i 7.3, 7.4, and 7.5 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 226941.
nvd
CVE-2026-16856P2HIGHCVSS 8.8v7.5v7.62026-08-12
CVE-2026-16856 [HIGH] CWE-78 CVE-2026-16856: IBM i 7.6, and 7.5 could allow a local attacker to gain elevated privileges due to improper neutrali
IBM i 7.6, and 7.5 could allow a local attacker to gain elevated privileges due to improper neutralization of special elements used in an OS command.
nvd
CVE-2026-17082P3HIGHCVSS 8.8v7.3v7.4+2 more2026-08-12
CVE-2026-17082 [HIGH] CWE-269 CVE-2026-17082: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improper validation of a client-supplied profile name.
nvd
CVE-2026-16904P3HIGHCVSS 8.1≥ 7.3, ≤ 7.6v7.6+3 more2026-08-12
CVE-2026-16904 [HIGH] CWE-269 CVE-2026-16904: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary comman
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper privilege management during monitor owner reassignment.
nvd
CVE-2026-2311P3CRITICALCVSS 9.8v7.2v7.3+8 more2026-04-30
CVE-2026-2311 [CRITICAL] CWE-284 CVE-2026-2311: IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 s vulnerable to privilege escalation caused by an invalid IBM i We
IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 s vulnerable to privilege escalation caused by an invalid IBM i Web Administration GUI authorization check. A malicious actor could cause user-controlled code to run with administrator privilege.
nvd
CVE-2026-16975P3HIGHCVSS 8.8v7.3v7.4+2 more2026-08-13
CVE-2026-16975 [HIGH] CWE-787 CVE-2026-16975: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code d
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to a heap-based buffer overflow.
nvd
CVE-2024-51463P3MEDIUMCVSS 5.4PoCv7.3v7.4+2 more2024-12-21
CVE-2024-51463 [MEDIUM] CWE-918 CVE-2024-51463: IBM i 7.3, 7.4, and 7.5 is vulnerable to server-side request forgery (SSRF). This may allow an aut
IBM i 7.3, 7.4, and 7.5
is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
nvd
CVE-2026-17223P3HIGHCVSS 8.8≥ 7.3, ≤ 7.6v7.6+3 more2026-08-13
CVE-2026-17223 [HIGH] CWE-787 CVE-2026-17223: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code d
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to a buffer overflow.
nvd
CVE-2026-17110P3HIGHCVSS 8.8≥ 7.3, ≤ 7.6v7.6+3 more2026-08-12
CVE-2026-17110 [HIGH] CWE-250 CVE-2026-17110: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary comman
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands and obtain sensitive information due to improper privilege management.
nvd
CVE-2025-33108P3HIGHCVSS 8.8v7.4v7.52025-06-14
CVE-2025-33108 [HIGH] CWE-250 CVE-2025-33108: IBM Backup, Recovery and Media Services for i 7.4 and 7.5 could allow a user with the capability to
IBM Backup, Recovery and Media Services for i 7.4 and 7.5 could allow a user with the capability to compile or restore a program to gain elevated privileges due to a library unqualified call made by a BRMS program. A malicious actor could cause user-controlled code to run with component access to the host operating system.
nvd
CVE-2026-16722P3HIGHCVSS 8.8v7.3v7.4+2 more2026-08-13
CVE-2026-16722 [HIGH] CWE-269 CVE-2026-16722: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain unauthorized priv
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain unauthorized privileges due to improper privilege management.
nvd
CVE-2025-36367P3HIGHCVSS 8.8v7.2v7.3+3 more2025-11-01
CVE-2025-36367 [HIGH] CWE-862 CVE-2025-36367: IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 is vulnerable to privilege escalation caused by an invalid IBM i S
IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 is vulnerable to privilege escalation caused by an invalid IBM i SQL services authorization check. A malicious actor can use the elevated privileges of another user profile to gain root access to the host operating system.
nvd
CVE-2026-18235P3HIGHCVSS 8.3≥ 7.3, ≤ 7.6v7.6+3 more2026-08-12
CVE-2026-18235 [HIGH] CWE-78 CVE-2026-18235: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary Contro
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary Control Language commands due to insufficient input validation.
nvd
CVE-2026-9072P3CRITICALCVSS 9.8≥ 7.3, ≤ 7.62026-06-22
CVE-2026-9072 [CRITICAL] CWE-94 CVE-2026-9072: IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - when using Intellige
IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - when using Intelligent Management with the WebSphere WebServer Plug-in component - are vulnerable to remote code execution and denial of service. This vulnerability can be exploited when an attacker impersonates backend servers and sends crafted responses to the plug-in.
nvd
CVE-2025-2947P3CRITICALCVSS 9.8v7.62025-04-17
CVE-2025-2947 [CRITICAL] CWE-278 CVE-2025-2947: IBM i 7.6 contains a privilege escalation vulnerability due to incorrect profile swapping in an OS
IBM i 7.6
contains a privilege escalation vulnerability due to incorrect profile swapping in an OS command. A malicious actor can use the command to elevate privileges to gain root access to the host operating system.
nvd
CVE-2026-7870P3HIGHCVSS 8.8v7.3v7.4+2 more2026-06-11
CVE-2026-7870 [HIGH] CWE-427 CVE-2026-7870: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a user to gain elevated privileges due to an unqualified li
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privilege.
nvd
CVE-2026-17095P3HIGHCVSS 8.3v7.3v7.4+2 more2026-08-12
CVE-2026-17095 [HIGH] CWE-915 CVE-2026-17095: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrict
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to unsafe reflection.
nvd
CVE-2026-16907P3HIGHCVSS 7.6≥ 7.3, ≤ 7.6v7.6+3 more2026-08-12
CVE-2026-16907 [HIGH] CWE-787 CVE-2026-16907: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code d
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to improper bounds checking.
nvd
CVE-2026-17206P3CRITICALCVSS 9.8≥ 7.3, ≤ 7.6v7.6+3 more2026-08-13
CVE-2026-17206 [CRITICAL] CWE-787 CVE-2026-17206: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a buffer
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a buffer overflow.
nvd
CVE-2026-17101P3CRITICALCVSS 9.6v7.3v7.4+2 more2026-08-13
CVE-2026-17101 [CRITICAL] CWE-287 CVE-2026-17101: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code or obtain sensi
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code or obtain sensitive information due to improper authentication.
nvd