Ibm I vulnerabilities
206 known vulnerabilities affecting ibm/i.
Total CVEs
206
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL21HIGH92MEDIUM87LOW6
Vulnerabilities
Page 3 of 11
CVE-2025-33103P3HIGHCVSS 8.8v7.2v7.3+3 more2025-05-17
CVE-2025-33103 [HIGH] CWE-250 CVE-2025-33103: IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 product IBM TCP/IP Connectivity Utilities for i contains a privile
IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 product IBM TCP/IP Connectivity Utilities for i contains a privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain root access to the host operating system.
nvd
CVE-2026-18341P3HIGHCVSS 8.8v7.3v7.4+2 more2026-09-04
CVE-2026-18341 [HIGH] CWE-122 CVE-2026-18341: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to corrupt memory due to an
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to corrupt memory due to an integer underflow.
nvd
CVE-2026-16815P3CRITICALCVSS 9.1v7.3v7.4+2 more2026-08-13
CVE-2026-16815 [CRITICAL] CWE-787 CVE-2026-16815: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and potentia
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and potentially obtain sensitive information due to a stack-based buffer overflow.
nvd
CVE-2026-17057P3CRITICALCVSS 9.1v7.3v7.4+2 more2026-09-04
CVE-2026-17057 [CRITICAL] CWE-306 CVE-2026-17057: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and affect d
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and affect data integrity due to missing authentication for critical functions.
nvd
CVE-2025-36004P3HIGHCVSS 8.8v7.2v7.3+2 more2025-06-25
CVE-2025-36004 [HIGH] CWE-427 CVE-2025-36004: IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user to gain elevated privileges due to an unqualified li
IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user to gain elevated privileges due to an unqualified library call in IBM Facsimile Support for i. A malicious actor could cause user-controlled code to run with administrator privilege.
nvd
CVE-2023-30990P3CRITICALCVSS 9.8v7.2v7.3+3 more2023-07-04
CVE-2023-30990 [CRITICAL] CWE-94 CVE-2023-30990: IBM i 7.2, 7.3, 7.4, and 7.5 could allow a remote attacker to execute CL commands as QUSER, caused b
IBM i 7.2, 7.3, 7.4, and 7.5 could allow a remote attacker to execute CL commands as QUSER, caused by an exploitation of DDM architecture. IBM X-Force ID: 254036.
nvd
CVE-2025-36119P3HIGHCVSS 8.8v7.3v7.4+2 more2025-08-08
CVE-2025-36119 [HIGH] CWE-290 CVE-2025-36119: IBM i 7.3, 7.4, 7.5, and 7.6 is affected by an authenticated user obtaining elevated privileges with
IBM i 7.3, 7.4, 7.5, and 7.6 is affected by an authenticated user obtaining elevated privileges with IBM Digital Certificate Manager for i (DCM) due to a web session hijacking vulnerability. An authenticated user without administrator privileges could exploit this vulnerability to perform actions in DCM as an administrator.
nvd
CVE-2024-51464P4MEDIUMCVSS 4.3PoCv7.3v7.4+2 more2024-12-21
CVE-2024-51464 [MEDIUM] CWE-288 CVE-2024-51464: IBM i 7.3, 7.4, and 7.5 is vulnerable to bypassing Navigator for i interface restrictions. By sendi
IBM i 7.3, 7.4, and 7.5 is vulnerable to bypassing Navigator for i interface restrictions. By sending a specially crafted request, an authenticated attacker could exploit this vulnerability to remotely perform operations that the user is not allowed to perform when using Navigator for i.
nvd
CVE-2026-16967P3HIGHCVSS 7.5v7.3v7.4+2 more2026-08-13
CVE-2026-16967 [HIGH] CWE-367 CVE-2026-16967: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized access
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized access to system objects due to a time-of-check to time-of-use (TOCTOU) race condition involving symbolic links.
nvd
CVE-2025-33109P3HIGHCVSS 8.8v7.2v7.3+4 more2025-07-24
CVE-2025-33109 [HIGH] CWE-250 CVE-2025-33109: IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to a privilege escalation caused by an invalid datab
IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to a privilege escalation caused by an invalid database authority check. A bad actor could execute a database procedure or function without having all required permissions, in addition to causing denial of service for some database actions.
nvd
CVE-2026-17029P3HIGHCVSS 8.8≥ 7.3, ≤ 7.6v7.6+3 more2026-08-13
CVE-2026-17029 [HIGH] CWE-787 CVE-2026-17029: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code due to an out-of
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code due to an out-of-bounds write.
nvd
CVE-2024-55898P3HIGHCVSS 8.5v7.2v7.3+3 more2025-02-24
CVE-2024-55898 [HIGH] CWE-427 CVE-2024-55898: IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user with the capability to compile or restore a program
IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user with the capability to compile or restore a program to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privilege.
nvd
CVE-2026-17207P3CRITICALCVSS 9.1v7.3v7.4+2 more2026-09-04
CVE-2026-17207 [CRITICAL] CWE-787 CVE-2026-17207: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and compromi
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and compromise integrity due to a buffer overflow.
nvd
CVE-2026-8858P3HIGHCVSS 8.8≥ 7.3, ≤ 7.62026-06-22
CVE-2026-8858 [HIGH] CWE-94 CVE-2026-8858: IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to remo
IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to remote code execution and denial of service in the WebSphere Web Server Plug-in component. This vulnerability can be exploited when an attacker impersonates the application server and sends crafted responses to the plug-in.
nvd
CVE-2026-17075P3HIGHCVSS 8.2v7.3v7.4+2 more2026-08-13
CVE-2026-17075 [HIGH] CWE-287 CVE-2026-17075: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information and perfo
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information and perform unauthorized operations due to improper validation of authentication tokens.
nvd
CVE-2026-17045P3HIGHCVSS 8.1≥ 7.3, ≤ 7.6v7.6+3 more2026-08-13
CVE-2026-17045 [HIGH] CWE-294 CVE-2026-17045: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to perform unauthorized ope
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to perform unauthorized operations and access sensitive information due to improper session management.
nvd
CVE-2026-4942P3HIGHCVSS 7.5v7.3v7.4+2 more2026-07-17
CVE-2026-4942 [HIGH] CWE-757 CVE-2026-4942: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to send a specifically crafted message an
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to send a specifically crafted message and downgrade the Transport Layer Security (TLS) protocol to a version disabled in the server configuration.
nvd
CVE-2026-18175P3HIGHCVSS 7.5v7.3v7.4+2 more2026-09-04
CVE-2026-18175 [HIGH] CWE-285 CVE-2026-18175: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipulate database transactions due t
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipulate database transactions due to improper authorization in the DDM target dispatcher.
nvd
CVE-2026-17220P3HIGHCVSS 8.2v7.3v7.4+2 more2026-08-13
CVE-2026-17220 [HIGH] CWE-120 CVE-2026-17220: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and modify a
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and modify authentication metadata due to a buffer overflow.
nvd
CVE-2026-18098P3HIGHCVSS 8.1v7.3v7.4+2 more2026-08-12
CVE-2026-18098 [HIGH] CWE-346 CVE-2026-18098: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive informa
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and compromise system integrity due to an XML injection flaw.
nvd