cbcvebase.

Ibm I vulnerabilities

68 known vulnerabilities affecting ibm/i.

Total CVEs
68
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH34MEDIUM27LOW3

Vulnerabilities

Page 4 of 4
CVE-2023-47741P4MEDIUMCVSS 5.3v7.3v7.4+2 more2023-12-18
CVE-2023-47741 [MEDIUM] CWE-522 CVE-2023-47741: IBM i 7.3, 7.4, 7.5, IBM i Db2 Mirror for i 7.4 and 7.5 web browser clients may leave clear-text pa IBM i 7.3, 7.4, 7.5, IBM i Db2 Mirror for i 7.4 and 7.5 web browser clients may leave clear-text passwords in browser memory that can be viewed using common browser tools before the memory is garbage collected. A malicious actor with access to the victim's PC could exploit this vulnerability to gain access to the IBM i operating system. IBM X-Force I
nvd
CVE-2022-43857P4MEDIUMCVSS 4.3v7.3v7.4+1 more2022-12-22
CVE-2022-43857 [MEDIUM] CWE-22 CVE-2022-43857: IBM Navigator for i 7.3, 7.4 and 7.5 could allow an authenticated user to access IBM Navigator for i IBM Navigator for i 7.3, 7.4 and 7.5 could allow an authenticated user to access IBM Navigator for i log files they are authorized to but not while using this interface. The remote authenticated user can bypass the interface checks and download log files by modifying servlet filter. IBM X-Force ID: 239301.
nvd
CVE-2022-43859P4MEDIUMCVSS 4.3v7.3v7.4+1 more2022-12-22
CVE-2022-43859 [MEDIUM] CWE-89 CVE-2022-43859: IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive informat IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information for an object they are authorized to but not while using this interface. By performing a UNION based SQL injection an attacker could see file permissions through this interface. IBM X-Force ID: 239304.
nvd
CVE-2022-43858P4MEDIUMCVSS 4.3v7.3v7.4+1 more2022-12-22
CVE-2022-43858 [MEDIUM] CWE-22 CVE-2022-43858: IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to access the file system an IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to access the file system and download files they are authorized to but not while using this interface. The remote authenticated user can bypass the interface checks by modifying a parameter thereby gaining access to their files through this interface. IBM X-Force ID: 239303.
nvd
CVE-2024-55897P4MEDIUMCVSS 4.3v7.4, 7.52025-01-03
CVE-2024-55897 [MEDIUM] CWE-614 CVE-2024-55897: IBM PowerHA SystemMirror for i 7.4 and 7.5 does not set the secure attribute on authorization toke IBM PowerHA SystemMirror for i 7.4 and 7.5 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value
nvd
CVE-2024-31870P4LOWCVSS 3.3v7.2v7.3+3 more2024-06-15
CVE-2024-31870 [LOW] CWE-204 CVE-2024-31870: IBM Db2 for i 7.2, 7.3, 7.4, and 7.5 supplies user defined table function is vulnerable to user enum IBM Db2 for i 7.2, 7.3, 7.4, and 7.5 supplies user defined table function is vulnerable to user enumeration by a local authenticated attacker, without having authority to the related *USRPRF objects. This can be used by a malicious actor to gather information about users that can be targeted in further attacks. IBM X-Force ID: 287174.
nvd
CVE-2020-4345P4LOWCVSS 3.3v7.2v7.3+1 more2020-05-17
CVE-2020-4345 [LOW] CWE-89 CVE-2020-4345: IBM i 7.2, 7.3, and 7.4 users running complex SQL statements under a specific set of circumstances m IBM i 7.2, 7.3, and 7.4 users running complex SQL statements under a specific set of circumstances may allow a local user to obtain sensitive information that they should not have access to. IBM X-Force ID: 178318.
nvd
CVE-2024-35122P4LOWCVSS 2.8v7.2v7.3+2 more2025-01-24
CVE-2024-35122 [LOW] CWE-266 CVE-2024-35122: IBM i 7.2, 7.3, 7.4, and 7.5 is vulnerable to a file level local denial of service caused by an insu IBM i 7.2, 7.3, 7.4, and 7.5 is vulnerable to a file level local denial of service caused by an insufficient authority requirement. A local non-privileged user can configure a referential constraint with the privileges of a user socially engineered to access the target file.
nvd
Ibm I vulnerabilities | cvebase