cbcvebase.

Ibm I vulnerabilities

68 known vulnerabilities affecting ibm/i.

Total CVEs
68
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH34MEDIUM27LOW3

Vulnerabilities

Page 3 of 4
CVE-2026-4942P3MEDIUMCVSS 5.9v7.6v7.5+2 more2026-07-17
CVE-2026-4942 [MEDIUM] CWE-757 CVE-2026-4942: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to send a specifically crafted message an IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to send a specifically crafted message and downgrade the Transport Layer Security (TLS) protocol to a version disabled in the server configuration.
nvd
CVE-2026-6936P3MEDIUMCVSS 6.5≥ 7.3, ≤ 7.6≥ 7.6, ≤ 11.5.9+3 more2026-05-27
CVE-2026-6936 [MEDIUM] CWE-674 CVE-2026-6936: IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to a denial-of-service attack due to uncontrolled recursio IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to a denial-of-service attack due to uncontrolled recursion in the Integrated Language Environment (ILE) compiler. An authenticated attacker could exploit this vulnerability by compiling specially crafted source code containing a specific combination of statements.
nvd
CVE-2017-1460P4HIGHCVSS 7.5v6.1v7.1+2 more2017-07-31
CVE-2017-1460 [HIGH] CWE-20 CVE-2017-1460: IBM i OSPF 6.1, 7.1, 7.2, and 7.3 is vulnerable when a rogue router spoofs its origin. Routing table IBM i OSPF 6.1, 7.1, 7.2, and 7.3 is vulnerable when a rogue router spoofs its origin. Routing tables are affected by a missing LSA, which may lead to loss of connectivity. IBM X-Force ID: 128379.
nvd
CVE-2024-52895P4MEDIUMCVSS 6.5v7.4v7.5+2 more2025-02-14
CVE-2024-52895 [MEDIUM] CWE-754 CVE-2024-52895: IBM i 7.4 and 7.5 is vulnerable to a database access denial of service caused by a bypass of a datab IBM i 7.4 and 7.5 is vulnerable to a database access denial of service caused by a bypass of a database capabilities restriction check. A privileged bad actor can remove or otherwise impact database infrastructure files resulting in incorrect behavior of software products that rely upon the database.
nvd
CVE-2021-3820P4HIGH≥ 0, < 0.3.72021-09-29
CVE-2021-3820 [HIGH] CWE-1333 inflect vulnerable to Inefficient Regular Expression Complexity inflect vulnerable to Inefficient Regular Expression Complexity inflect is customizable inflections for nodejs. inflect is vulnerable to Inefficient Regular Expression Complexity
ghsaosv
CVE-2022-40746P4MEDIUMCVSS 6.7≥ 1.1.2, < 1.1.4≥ 1.1.4.3, < 1.1.9.02022-11-21
CVE-2022-40746 [MEDIUM] CWE-77 CVE-2022-40746: IBM i Access Family 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.0 could allow a local authenticate IBM i Access Family 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.0 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability. By placing a specially crafted file in a compromised folder, an attacker could exploit this vulnerability to execute arbitrary code on the system. I
nvd
CVE-2025-3218P4MEDIUMCVSS 5.4v7.2v7.3+3 more2025-05-07
CVE-2025-3218 [MEDIUM] CWE-295 CVE-2025-3218: IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to authentication and authorization attacks due to i IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to authentication and authorization attacks due to incorrect validation processing in IBM i Netserver. A malicious actor could use the weaknesses, in conjunction with brute force authentication attacks or to bypass authority restrictions, to access the server.
nvd
CVE-2021-39056P4MEDIUMCVSS 6.5v7.1v7.2+2 more2022-01-13
CVE-2021-39056 [MEDIUM] CVE-2021-39056: The IBM i 7.1, 7.2, 7.3, and 7.4 Extended Dynamic Remote SQL server (EDRSQL) could allow a remote au The IBM i 7.1, 7.2, 7.3, and 7.4 Extended Dynamic Remote SQL server (EDRSQL) could allow a remote authenticated user to send a specially crafted request and cause a denial of service. IBM X-Force ID: 214537.
nvd
CVE-2019-4536P4MEDIUMCVSS 6.3v7.42019-08-29
CVE-2019-4536 [MEDIUM] CWE-269 CVE-2019-4536: IBM i 7.4 users who have done a Restore User Profile (RSTUSRPRF) on a system which has been configur IBM i 7.4 users who have done a Restore User Profile (RSTUSRPRF) on a system which has been configured with Db2 Mirror for i might have user profiles with elevated privileges caused by incorrect processing during a restore of multiple user profiles. A user with restore privileges could exploit this vulnerability to obtain elevated privileges on the re
nvd
CVE-2022-22481P4MEDIUMCVSS 5.3v7.2v7.3+1 more2022-05-09
CVE-2022-22481 [MEDIUM] CVE-2022-22481: IBM Navigator for i 7.2, 7.3, and 7.4 (heritage version) could allow a remote attacker to obtain acc IBM Navigator for i 7.2, 7.3, and 7.4 (heritage version) could allow a remote attacker to obtain access to the web interface without valid credentials. By modifying the sign on request, an attacker can gain visibility to the fully qualified domain name of the target system and the navigator tasks page, however they do not gain the ability to perform those t
nvd
CVE-2025-2950P4MEDIUMCVSS 5.4v7.3v7.4+2 more2025-04-18
CVE-2025-2950 [MEDIUM] CWE-644 CVE-2025-2950: IBM i 7.3, 7.4, 7.5, and 7.5 is vulnerable to a host header injection attack caused by improper neut IBM i 7.3, 7.4, 7.5, and 7.5 is vulnerable to a host header injection attack caused by improper neutralization of HTTP header content by IBM Navigator for i. An authenticated user can manipulate the host header in HTTP requests to change domain/IP address which may lead to unexpected behavior.
nvd
CVE-2024-55896P4MEDIUMCVSS 5.4v7.4v7.5+1 more2025-01-03
CVE-2024-55896 [MEDIUM] CWE-451 CVE-2024-55896: IBM PowerHA SystemMirror for i 7.4 and 7.5 contains improper restrictions when rendering content via IBM PowerHA SystemMirror for i 7.4 and 7.5 contains improper restrictions when rendering content via iFrames. This vulnerability could allow an attacker to gain improper access and perform unauthorized actions on the system.
nvd
CVE-2024-31878P4MEDIUMCVSS 5.3v7.2v7.3+3 more2024-06-07
CVE-2024-31878 [MEDIUM] CWE-203 CVE-2024-31878: IBM i 7.2, 7.3, 7.4, and 7.5 Service Tools Server (SST) is vulnerable to SST user enumeration by a r IBM i 7.2, 7.3, 7.4, and 7.5 Service Tools Server (SST) is vulnerable to SST user enumeration by a remote attacker. This vulnerability can be used by a malicious actor to gather information about SST users that can be targeted in further attacks. IBM X-Force ID: 287538.
nvd
CVE-2019-4040P4MEDIUMCVSS 6.1v7.2v7.32019-01-31
CVE-2019-4040 [MEDIUM] CWE-79 CVE-2019-4040: IBM I 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed ar IBM I 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 156164.
nvd
CVE-2021-38876P4MEDIUMCVSS 6.1v7.2v7.3+1 more2021-12-30
CVE-2021-38876 [MEDIUM] CWE-79 CVE-2021-38876: IBM i 7.2, 7.3, and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to em IBM i 7.2, 7.3, and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 208404.
nvd
CVE-2019-4450P4MEDIUMCVSS 6.1v7.2v7.3+1 more2019-11-09
CVE-2019-4450 [MEDIUM] CWE-79 CVE-2019-4450: IBM i 7.2, 7.3, and 7.4 for i is vulnerable to cross-site scripting. This vulnerability allows users IBM i 7.2, 7.3, and 7.4 for i is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 163492.
nvd
CVE-2019-4381P4MEDIUMCVSS 5.5v7.2v7.3+1 more2019-06-14
CVE-2019-4381 [MEDIUM] CWE-255 CVE-2019-4381: IBM i 7.27.3 Clustering could allow a local attacker to obtain sensitive information, caused by the IBM i 7.27.3 Clustering could allow a local attacker to obtain sensitive information, caused by the use of advanced node failure detection using the REST API to interface with the HMC. An attacker could exploit this vulnerability to obtain HMC credentials. IBM X-Force ID: 162159.
nvd
CVE-2022-34358P4MEDIUMCVSS 5.4v7.2v7.3+2 more2022-07-13
CVE-2022-34358 [MEDIUM] CWE-79 CVE-2022-34358: IBM i 7.2, 7.3, 7.4, and 7.5 is vulnerable to cross-site scripting. This vulnerability allows users IBM i 7.2, 7.3, 7.4, and 7.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 230516.
nvd
CVE-2023-42006P4MEDIUMCVSS 5.5v7.2v7.3+3 more2023-12-01
CVE-2023-42006 [MEDIUM] CWE-863 CVE-2023-42006: IBM Administration Runtime Expert for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to obtain se IBM Administration Runtime Expert for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to obtain sensitive information caused by improper authority checks. IBM X-Force ID: 265266.
nvd
CVE-2022-43860P4MEDIUMCVSS 4.3v7.3v7.4+1 more2022-12-24
CVE-2022-43860 [MEDIUM] CWE-89 CVE-2022-43860: IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive informat IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information they are authorized to but not while using this interface. By performing an SQL injection an attacker could see user profile attributes through this interface. IBM X-Force ID: 239305.
nvd
Ibm I vulnerabilities | cvebase