Ibm I vulnerabilities
68 known vulnerabilities affecting ibm/i.
Total CVEs
68
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH34MEDIUM27LOW3
Vulnerabilities
Page 3 of 4
CVE-2026-4942P3MEDIUMCVSS 5.9v7.6v7.5+2 more2026-07-17
CVE-2026-4942 [MEDIUM] CWE-757 CVE-2026-4942: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to send a specifically crafted message an
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to send a specifically crafted message and downgrade the Transport Layer Security (TLS) protocol to a version disabled in the server configuration.
nvd
CVE-2026-6936P3MEDIUMCVSS 6.5≥ 7.3, ≤ 7.6≥ 7.6, ≤ 11.5.9+3 more2026-05-27
CVE-2026-6936 [MEDIUM] CWE-674 CVE-2026-6936: IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to a denial-of-service attack due to uncontrolled recursio
IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to a denial-of-service attack due to uncontrolled recursion in the Integrated Language Environment (ILE) compiler. An authenticated attacker could exploit this vulnerability by compiling specially crafted source code containing a specific combination of statements.
nvd
CVE-2017-1460P4HIGHCVSS 7.5v6.1v7.1+2 more2017-07-31
CVE-2017-1460 [HIGH] CWE-20 CVE-2017-1460: IBM i OSPF 6.1, 7.1, 7.2, and 7.3 is vulnerable when a rogue router spoofs its origin. Routing table
IBM i OSPF 6.1, 7.1, 7.2, and 7.3 is vulnerable when a rogue router spoofs its origin. Routing tables are affected by a missing LSA, which may lead to loss of connectivity. IBM X-Force ID: 128379.
nvd
CVE-2024-52895P4MEDIUMCVSS 6.5v7.4v7.5+2 more2025-02-14
CVE-2024-52895 [MEDIUM] CWE-754 CVE-2024-52895: IBM i 7.4 and 7.5 is vulnerable to a database access denial of service caused by a bypass of a datab
IBM i 7.4 and 7.5 is vulnerable to a database access denial of service caused by a bypass of a database capabilities restriction check. A privileged bad actor can remove or otherwise impact database infrastructure files resulting in incorrect behavior of software products that rely upon the database.
nvd
CVE-2021-3820P4HIGH≥ 0, < 0.3.72021-09-29
CVE-2021-3820 [HIGH] CWE-1333 inflect vulnerable to Inefficient Regular Expression Complexity
inflect vulnerable to Inefficient Regular Expression Complexity
inflect is customizable inflections for nodejs. inflect is vulnerable to Inefficient Regular Expression Complexity
ghsaosv
CVE-2022-40746P4MEDIUMCVSS 6.7≥ 1.1.2, < 1.1.4≥ 1.1.4.3, < 1.1.9.02022-11-21
CVE-2022-40746 [MEDIUM] CWE-77 CVE-2022-40746: IBM i Access Family 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.0 could allow a local authenticate
IBM i Access Family 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.0 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability. By placing a specially crafted file in a compromised folder, an attacker could exploit this vulnerability to execute arbitrary code on the system. I
nvd
CVE-2025-3218P4MEDIUMCVSS 5.4v7.2v7.3+3 more2025-05-07
CVE-2025-3218 [MEDIUM] CWE-295 CVE-2025-3218: IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to authentication and authorization attacks due to i
IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to authentication and authorization attacks due to incorrect validation processing in IBM i Netserver. A malicious actor could use the weaknesses, in conjunction with brute force authentication attacks or to bypass authority restrictions, to access the server.
nvd
CVE-2021-39056P4MEDIUMCVSS 6.5v7.1v7.2+2 more2022-01-13
CVE-2021-39056 [MEDIUM] CVE-2021-39056: The IBM i 7.1, 7.2, 7.3, and 7.4 Extended Dynamic Remote SQL server (EDRSQL) could allow a remote au
The IBM i 7.1, 7.2, 7.3, and 7.4 Extended Dynamic Remote SQL server (EDRSQL) could allow a remote authenticated user to send a specially crafted request and cause a denial of service. IBM X-Force ID: 214537.
nvd
CVE-2019-4536P4MEDIUMCVSS 6.3v7.42019-08-29
CVE-2019-4536 [MEDIUM] CWE-269 CVE-2019-4536: IBM i 7.4 users who have done a Restore User Profile (RSTUSRPRF) on a system which has been configur
IBM i 7.4 users who have done a Restore User Profile (RSTUSRPRF) on a system which has been configured with Db2 Mirror for i might have user profiles with elevated privileges caused by incorrect processing during a restore of multiple user profiles. A user with restore privileges could exploit this vulnerability to obtain elevated privileges on the re
nvd
CVE-2022-22481P4MEDIUMCVSS 5.3v7.2v7.3+1 more2022-05-09
CVE-2022-22481 [MEDIUM] CVE-2022-22481: IBM Navigator for i 7.2, 7.3, and 7.4 (heritage version) could allow a remote attacker to obtain acc
IBM Navigator for i 7.2, 7.3, and 7.4 (heritage version) could allow a remote attacker to obtain access to the web interface without valid credentials. By modifying the sign on request, an attacker can gain visibility to the fully qualified domain name of the target system and the navigator tasks page, however they do not gain the ability to perform those t
nvd
CVE-2025-2950P4MEDIUMCVSS 5.4v7.3v7.4+2 more2025-04-18
CVE-2025-2950 [MEDIUM] CWE-644 CVE-2025-2950: IBM i 7.3, 7.4, 7.5, and 7.5 is vulnerable to a host header injection attack caused by improper neut
IBM i 7.3, 7.4, 7.5, and 7.5 is vulnerable to a host header injection attack caused by improper neutralization of HTTP header content by IBM Navigator for i. An authenticated user can manipulate the host header in HTTP requests to change domain/IP address which may lead to unexpected behavior.
nvd
CVE-2024-55896P4MEDIUMCVSS 5.4v7.4v7.5+1 more2025-01-03
CVE-2024-55896 [MEDIUM] CWE-451 CVE-2024-55896: IBM PowerHA SystemMirror for i 7.4 and 7.5 contains improper restrictions when rendering content via
IBM PowerHA SystemMirror for i 7.4 and 7.5 contains improper restrictions when rendering content via iFrames. This vulnerability could allow an attacker to gain improper access and perform unauthorized actions on the system.
nvd
CVE-2024-31878P4MEDIUMCVSS 5.3v7.2v7.3+3 more2024-06-07
CVE-2024-31878 [MEDIUM] CWE-203 CVE-2024-31878: IBM i 7.2, 7.3, 7.4, and 7.5 Service Tools Server (SST) is vulnerable to SST user enumeration by a r
IBM i 7.2, 7.3, 7.4, and 7.5 Service Tools Server (SST) is vulnerable to SST user enumeration by a remote attacker. This vulnerability can be used by a malicious actor to gather information about SST users that can be targeted in further attacks. IBM X-Force ID: 287538.
nvd
CVE-2019-4040P4MEDIUMCVSS 6.1v7.2v7.32019-01-31
CVE-2019-4040 [MEDIUM] CWE-79 CVE-2019-4040: IBM I 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed ar
IBM I 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 156164.
nvd
CVE-2021-38876P4MEDIUMCVSS 6.1v7.2v7.3+1 more2021-12-30
CVE-2021-38876 [MEDIUM] CWE-79 CVE-2021-38876: IBM i 7.2, 7.3, and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to em
IBM i 7.2, 7.3, and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 208404.
nvd
CVE-2019-4450P4MEDIUMCVSS 6.1v7.2v7.3+1 more2019-11-09
CVE-2019-4450 [MEDIUM] CWE-79 CVE-2019-4450: IBM i 7.2, 7.3, and 7.4 for i is vulnerable to cross-site scripting. This vulnerability allows users
IBM i 7.2, 7.3, and 7.4 for i is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 163492.
nvd
CVE-2019-4381P4MEDIUMCVSS 5.5v7.2v7.3+1 more2019-06-14
CVE-2019-4381 [MEDIUM] CWE-255 CVE-2019-4381: IBM i 7.27.3 Clustering could allow a local attacker to obtain sensitive information, caused by the
IBM i 7.27.3 Clustering could allow a local attacker to obtain sensitive information, caused by the use of advanced node failure detection using the REST API to interface with the HMC. An attacker could exploit this vulnerability to obtain HMC credentials. IBM X-Force ID: 162159.
nvd
CVE-2022-34358P4MEDIUMCVSS 5.4v7.2v7.3+2 more2022-07-13
CVE-2022-34358 [MEDIUM] CWE-79 CVE-2022-34358: IBM i 7.2, 7.3, 7.4, and 7.5 is vulnerable to cross-site scripting. This vulnerability allows users
IBM i 7.2, 7.3, 7.4, and 7.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 230516.
nvd
CVE-2023-42006P4MEDIUMCVSS 5.5v7.2v7.3+3 more2023-12-01
CVE-2023-42006 [MEDIUM] CWE-863 CVE-2023-42006: IBM Administration Runtime Expert for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to obtain se
IBM Administration Runtime Expert for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to obtain sensitive information caused by improper authority checks. IBM X-Force ID: 265266.
nvd
CVE-2022-43860P4MEDIUMCVSS 4.3v7.3v7.4+1 more2022-12-24
CVE-2022-43860 [MEDIUM] CWE-89 CVE-2022-43860: IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive informat
IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information they are authorized to but not while using this interface. By performing an SQL injection an attacker could see user profile attributes through this interface. IBM X-Force ID: 239305.
nvd