Ibm I vulnerabilities

61 known vulnerabilities affecting ibm/i.

Total CVEs
61
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH31MEDIUM25LOW3

Vulnerabilities

Page 3 of 4
CVE-2023-30990CRITICALCVSS 9.8v7.2v7.3+3 more2023-07-04
CVE-2023-30990 [CRITICAL] CWE-94 CVE-2023-30990: IBM i 7.2, 7.3, 7.4, and 7.5 could allow a remote attacker to execute CL commands as QUSER, caused b IBM i 7.2, 7.3, 7.4, and 7.5 could allow a remote attacker to execute CL commands as QUSER, caused by an exploitation of DDM architecture. IBM X-Force ID: 254036.
cvelistv5nvd
CVE-2023-23470HIGHCVSS 7.2v7.2v7.3+3 more2023-05-04
CVE-2023-23470 [HIGH] CWE-89 CVE-2023-23470: IBM i 7.2, 7.3, 7.4, and 7.5 could allow an authenticated privileged administrator to gain elevated IBM i 7.2, 7.3, 7.4, and 7.5 could allow an authenticated privileged administrator to gain elevated privileges in non-default configurations, as a result of improper SQL processing. By using a specially crafted SQL operation, the administrator could exploit the vulnerability to perform additional administrator operations. IBM X-Force ID: 244510.
cvelistv5nvd
CVE-2022-43860MEDIUMCVSS 4.3v7.3v7.4+1 more2022-12-24
CVE-2022-43860 [MEDIUM] CWE-89 CVE-2022-43860: IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive informat IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information they are authorized to but not while using this interface. By performing an SQL injection an attacker could see user profile attributes through this interface. IBM X-Force ID: 239305.
nvd
CVE-2022-43859MEDIUMCVSS 4.3v7.3v7.4+1 more2022-12-22
CVE-2022-43859 [MEDIUM] CWE-89 CVE-2022-43859: IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive informat IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information for an object they are authorized to but not while using this interface. By performing a UNION based SQL injection an attacker could see file permissions through this interface. IBM X-Force ID: 239304.
nvd
CVE-2022-43858MEDIUMCVSS 4.3v7.3v7.4+1 more2022-12-22
CVE-2022-43858 [MEDIUM] CWE-22 CVE-2022-43858: IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to access the file system an IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to access the file system and download files they are authorized to but not while using this interface. The remote authenticated user can bypass the interface checks by modifying a parameter thereby gaining access to their files through this interface. IBM X-Force ID: 239303.
nvd
CVE-2022-43857MEDIUMCVSS 4.3v7.3v7.4+1 more2022-12-22
CVE-2022-43857 [MEDIUM] CWE-22 CVE-2022-43857: IBM Navigator for i 7.3, 7.4 and 7.5 could allow an authenticated user to access IBM Navigator for i IBM Navigator for i 7.3, 7.4 and 7.5 could allow an authenticated user to access IBM Navigator for i log files they are authorized to but not while using this interface. The remote authenticated user can bypass the interface checks and download log files by modifying servlet filter. IBM X-Force ID: 239301.
nvd
CVE-2022-40746MEDIUMCVSS 6.7≥ 1.1.2, < 1.1.4≥ 1.1.4.3, < 1.1.9.02022-11-21
CVE-2022-40746 [MEDIUM] CWE-77 CVE-2022-40746: IBM i Access Family 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.0 could allow a local authenticate IBM i Access Family 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.0 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability. By placing a specially crafted file in a compromised folder, an attacker could exploit this vulnerability to execute arbitrary code on the system. I
cvelistv5nvd
CVE-2022-34358MEDIUMCVSS 5.4v7.2v7.3+2 more2022-07-13
CVE-2022-34358 [MEDIUM] CWE-79 CVE-2022-34358: IBM i 7.2, 7.3, 7.4, and 7.5 is vulnerable to cross-site scripting. This vulnerability allows users IBM i 7.2, 7.3, 7.4, and 7.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 230516.
cvelistv5nvd
CVE-2022-22495HIGHCVSS 8.8v7.3v7.4+1 more2022-05-24
CVE-2022-22495 [HIGH] CWE-89 CVE-2022-22495: IBM i 7.3, 7.4, and 7.5 is vulnerable to SQL injection. A remote attacker could send specially craft IBM i 7.3, 7.4, and 7.5 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 226941.
cvelistv5nvd
CVE-2022-22481MEDIUMCVSS 5.3v7.2v7.3+1 more2022-05-09
CVE-2022-22481 [MEDIUM] CVE-2022-22481: IBM Navigator for i 7.2, 7.3, and 7.4 (heritage version) could allow a remote attacker to obtain acc IBM Navigator for i 7.2, 7.3, and 7.4 (heritage version) could allow a remote attacker to obtain access to the web interface without valid credentials. By modifying the sign on request, an attacker can gain visibility to the fully qualified domain name of the target system and the navigator tasks page, however they do not gain the ability to perform those t
cvelistv5nvd
CVE-2021-39056MEDIUMCVSS 6.5v7.1v7.2+2 more2022-01-13
CVE-2021-39056 [MEDIUM] CVE-2021-39056: The IBM i 7.1, 7.2, 7.3, and 7.4 Extended Dynamic Remote SQL server (EDRSQL) could allow a remote au The IBM i 7.1, 7.2, 7.3, and 7.4 Extended Dynamic Remote SQL server (EDRSQL) could allow a remote authenticated user to send a specially crafted request and cause a denial of service. IBM X-Force ID: 214537.
cvelistv5nvd
CVE-2021-38876MEDIUMCVSS 6.1v7.2v7.3+1 more2021-12-30
CVE-2021-38876 [MEDIUM] CWE-79 CVE-2021-38876: IBM i 7.2, 7.3, and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to em IBM i 7.2, 7.3, and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 208404.
cvelistv5nvd
CVE-2021-3820HIGH≥ 0, < 0.3.72021-09-29
CVE-2021-3820 [HIGH] CWE-1333 inflect vulnerable to Inefficient Regular Expression Complexity inflect vulnerable to Inefficient Regular Expression Complexity inflect is customizable inflections for nodejs. inflect is vulnerable to Inefficient Regular Expression Complexity
ghsaosv
CVE-2021-20501HIGHCVSS 8.2v7.1v7.2+2 more2021-04-21
CVE-2021-20501 [HIGH] CVE-2021-20501: IBM i 7.1, 7.2, 7.3, and 7.4 SMTP allows a network attacker to send emails to non-existent local-dom IBM i 7.1, 7.2, 7.3, and 7.4 SMTP allows a network attacker to send emails to non-existent local-domain recipients to the SMTP server, caused by using a non-default configuration. An attacker could exploit this vulnerability to consume unnecessary network bandwidth and disk space, and allow remote attackers to send spam email. IBM X-Force ID: 198056.
cvelistv5nvd
CVE-2020-4345LOWCVSS 3.3v7.2v7.3+1 more2020-05-17
CVE-2020-4345 [LOW] CWE-89 CVE-2020-4345: IBM i 7.2, 7.3, and 7.4 users running complex SQL statements under a specific set of circumstances m IBM i 7.2, 7.3, and 7.4 users running complex SQL statements under a specific set of circumstances may allow a local user to obtain sensitive information that they should not have access to. IBM X-Force ID: 178318.
cvelistv5nvd
CVE-2019-4450MEDIUMCVSS 6.1v7.2v7.3+1 more2019-11-09
CVE-2019-4450 [MEDIUM] CWE-79 CVE-2019-4450: IBM i 7.2, 7.3, and 7.4 for i is vulnerable to cross-site scripting. This vulnerability allows users IBM i 7.2, 7.3, and 7.4 for i is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 163492.
cvelistv5nvd
CVE-2019-4536MEDIUMCVSS 6.3v7.42019-08-29
CVE-2019-4536 [MEDIUM] CWE-269 CVE-2019-4536: IBM i 7.4 users who have done a Restore User Profile (RSTUSRPRF) on a system which has been configur IBM i 7.4 users who have done a Restore User Profile (RSTUSRPRF) on a system which has been configured with Db2 Mirror for i might have user profiles with elevated privileges caused by incorrect processing during a restore of multiple user profiles. A user with restore privileges could exploit this vulnerability to obtain elevated privileges on the re
cvelistv5nvd
CVE-2019-4381MEDIUMCVSS 5.5v7.2v7.3+1 more2019-06-14
CVE-2019-4381 [MEDIUM] CWE-255 CVE-2019-4381: IBM i 7.27.3 Clustering could allow a local attacker to obtain sensitive information, caused by the IBM i 7.27.3 Clustering could allow a local attacker to obtain sensitive information, caused by the use of advanced node failure detection using the REST API to interface with the HMC. An attacker could exploit this vulnerability to obtain HMC credentials. IBM X-Force ID: 162159.
cvelistv5nvd
CVE-2019-4040MEDIUMCVSS 6.1v7.2v7.32019-01-31
CVE-2019-4040 [MEDIUM] CWE-79 CVE-2019-4040: IBM I 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed ar IBM I 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 156164.
cvelistv5nvd
CVE-2017-1460HIGHCVSS 7.5v6.1v7.1+2 more2017-07-31
CVE-2017-1460 [HIGH] CWE-20 CVE-2017-1460: IBM i OSPF 6.1, 7.1, 7.2, and 7.3 is vulnerable when a rogue router spoofs its origin. Routing table IBM i OSPF 6.1, 7.1, 7.2, and 7.3 is vulnerable when a rogue router spoofs its origin. Routing tables are affected by a missing LSA, which may lead to loss of connectivity. IBM X-Force ID: 128379.
cvelistv5nvd