cbcvebase.

Ibm I vulnerabilities

206 known vulnerabilities affecting ibm/i.

Total CVEs
206
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL21HIGH92MEDIUM87LOW6

Vulnerabilities

Page 4 of 11
CVE-2026-18101P3HIGHCVSS 8.8v7.3v7.4+2 more2026-08-13
CVE-2026-18101 [HIGH] CWE-269 CVE-2026-18101: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to imprope IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper management of thread authority swaps.
nvd
CVE-2026-18511P3HIGHCVSS 7.8v7.3v7.4+2 more2026-08-13
CVE-2026-18511 [HIGH] CWE-787 CVE-2026-18511: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to generate a stack-based bu IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to generate a stack-based buffer overflow in the Native IBM i JSSE provider, caused by improper bounds checking during TLS session establishment. A local attacker could overflow a fixed-length buffer and execute arbitrary code on the system or cause the JVM process to crash.
nvd
CVE-2024-31879P3HIGHCVSS 7.5v7.2v7.3+2 more2024-05-18
CVE-2024-31879 [HIGH] CWE-502 CVE-2024-31879: IBM i 7.2, 7.3, and 7.4 could allow a remote attacker to execute arbitrary code leading to a denial IBM i 7.2, 7.3, and 7.4 could allow a remote attacker to execute arbitrary code leading to a denial of service of network ports on the system, caused by the deserialization of untrusted data. IBM X-Force ID: 287539.
nvd
CVE-2026-16826P3HIGHCVSS 7.8v7.3v7.4+2 more2026-09-04
CVE-2026-16826 [HIGH] CWE-78 CVE-2026-16826: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary commands due to impro IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
nvd
CVE-2026-17499P3HIGHCVSS 7.8v7.3v7.4+2 more2026-09-04
CVE-2026-17499 [HIGH] CWE-78 CVE-2026-17499: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary commands due to impro IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
nvd
CVE-2021-20501P3HIGHCVSS 8.2v7.1v7.2+2 more2021-04-21
CVE-2021-20501 [HIGH] CVE-2021-20501: IBM i 7.1, 7.2, 7.3, and 7.4 SMTP allows a network attacker to send emails to non-existent local-dom IBM i 7.1, 7.2, 7.3, and 7.4 SMTP allows a network attacker to send emails to non-existent local-domain recipients to the SMTP server, caused by using a non-default configuration. An attacker could exploit this vulnerability to consume unnecessary network bandwidth and disk space, and allow remote attackers to send spam email. IBM X-Force ID: 198056.
nvd
CVE-2026-18846P3HIGHCVSS 7.5≥ 7.3, ≤ 7.6v7.6+3 more2026-08-13
CVE-2026-18846 [HIGH] CWE-787 CVE-2026-18846: IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to a buffer overflow from improperly validating client dat IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to a buffer overflow from improperly validating client data. By sending malformed requests to one of the host servers, a remote attacker could leverage this vulnerability to cause a denial-of-server (DoS) for that server.
nvd
CVE-2025-33122P3HIGHCVSS 7.5v7.2v7.3+3 more2025-06-17
CVE-2025-33122 [HIGH] CWE-427 CVE-2025-33122: IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 could allow a user to gain elevated privileges due to an unqualifi IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 could allow a user to gain elevated privileges due to an unqualified library call in IBM Advanced Job Scheduler for i. A malicious actor could cause user-controlled code to run with administrator privilege.
nvd
CVE-2026-16898P3HIGHCVSS 7.8v7.3v7.4+2 more2026-08-13
CVE-2026-16898 [HIGH] CWE-73 CVE-2026-16898: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to change the ownership of a IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to change the ownership of arbitrary files due to improper validation of an attacker-controlled file path.
nvd
CVE-2026-84414P3HIGHCVSS 7.8≥ 7.3, ≤ 7.6v7.6+3 more2026-09-29
CVE-2026-84414 [HIGH] CWE-732 CVE-2026-84414: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to change the ownership of a IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to change the ownership of arbitrary files due to improper validation of an attacker-controlled file path.
nvd
CVE-2026-17069P3HIGHCVSS 7.3≥ 7.3, ≤ 7.6v7.6+3 more2026-08-13
CVE-2026-17069 [HIGH] CWE-352 CVE-2026-17069: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrict IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper validation of anti-CSRF tokens.
nvd
CVE-2026-17418P3HIGHCVSS 7.8≥ 7.3, ≤ 7.6v7.6+3 more2026-08-12
CVE-2026-17418 [HIGH] CWE-89 CVE-2026-17418: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to improper neutralization of special elements used in an SQL command.
nvd
CVE-2023-43064P3HIGHCVSS 7.8v7.2v7.3+3 more2023-12-25
CVE-2023-43064 [HIGH] CWE-427 CVE-2023-43064: Facsimile Support for IBM i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privile Facsimile Support for IBM i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqualified library call. A malicious actor could cause arbitrary code to run with the privilege of the user invoking the facsimile support. IBM X-Force ID: 267689.
nvd
CVE-2026-16987P3HIGHCVSS 7.8v7.3v7.4+2 more2026-08-13
CVE-2026-16987 [HIGH] CWE-73 CVE-2026-16987: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to imprope IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper validation of the LANG environment variable.
nvd
CVE-2026-18077P3HIGHCVSS 7.5v7.3v7.4+2 more2026-08-13
CVE-2026-18077 [HIGH] CWE-787 CVE-2026-18077: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a sta IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a stack-based buffer overflow.
nvd
CVE-2026-16853P3HIGHCVSS 7.5v7.3v7.4+2 more2026-08-13
CVE-2026-16853 [HIGH] CWE-125 CVE-2026-16853: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.
nvd
CVE-2026-17099P3HIGHCVSS 7.3v7.3v7.4+2 more2026-08-13
CVE-2026-17099 [HIGH] CWE-287 CVE-2026-17099: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to im IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to improper authentication.
nvd
CVE-2026-17419P3MEDIUMCVSS 6.5≥ 7.3, ≤ 7.6v7.6+3 more2026-08-12
CVE-2026-17419 [MEDIUM] CWE-89 CVE-2026-17419: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to modify SQL tables due to IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to modify SQL tables due to improper neutralization of special elements used in an SQL command.
nvd
CVE-2024-25050P3HIGHCVSS 7.8v7.2v7.3+3 more2024-04-28
CVE-2024-25050 [HIGH] CWE-427 CVE-2024-25050: IBM i 7.2, 7.3, 7.4, 7.5 and IBM Rational Development Studio for i 7.2, 7.3, 7.4, 7.5 networking and IBM i 7.2, 7.3, 7.4, 7.5 and IBM Rational Development Studio for i 7.2, 7.3, 7.4, 7.5 networking and compiler infrastructure could allow a local user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privileges. IBM X-Force ID: 283242.
nvd
CVE-2026-16863P3HIGHCVSS 7.7≥ 7.3, ≤ 7.6v7.6+3 more2026-08-12
CVE-2026-16863 [HIGH] CWE-125 CVE-2026-16863: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive informa IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to an out-of-bounds read.
nvd
Ibm I vulnerabilities | cvebase