Ibm I vulnerabilities
206 known vulnerabilities affecting ibm/i.
Total CVEs
206
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL21HIGH92MEDIUM87LOW6
Vulnerabilities
Page 5 of 11
CVE-2024-31890P3HIGHCVSS 7.8≥ 7.3, ≤ 7.5v7.3, 7.4, 7.52024-06-21
CVE-2024-31890 [HIGH] CWE-250 CVE-2024-31890: IBM i 7.3, 7.4, and 7.5 product IBM TCP/IP Connectivity Utilities for i contains a local privilege e
IBM i 7.3, 7.4, and 7.5 product IBM TCP/IP Connectivity Utilities for i contains a local privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain root access to the host operating system. IBM X-Force ID: 288171.
nvd
CVE-2023-40685P3HIGHCVSS 7.8v7.2v7.3+3 more2023-10-29
CVE-2023-40685 [HIGH] CWE-269 CVE-2023-40685: Management Central as part of IBM i 7.2, 7.3, 7.4, and 7.5 Navigator contains a local privilege esca
Management Central as part of IBM i 7.2, 7.3, 7.4, and 7.5 Navigator contains a local privilege escalation vulnerability. A malicious actor with command line access to the operating system can exploit this vulnerability to elevate privileges to gain root access to the operating system. IBM X-Force ID: 264116.
nvd
CVE-2026-18071P3HIGHCVSS 7.8v7.3v7.4+2 more2026-08-13
CVE-2026-18071 [HIGH] CWE-269 CVE-2026-18071: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to imprope
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper privilege management.
nvd
CVE-2026-16887P3HIGHCVSS 7.5v7.62026-08-13
CVE-2026-16887 [HIGH] CWE-787 CVE-2026-16887: IBM i 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.
IBM i 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.
nvd
CVE-2013-5385P3HIGHCVSS 8.5v6.1v7.12014-01-02
CVE-2013-5385 [HIGH] CVE-2013-5385: The OSPF implementation in IBM i 6.1 and 7.1, in z/OS on zSeries servers, and in Networking Operatin
The OSPF implementation in IBM i 6.1 and 7.1, in z/OS on zSeries servers, and in Networking Operating System (aka NOS, formerly BLADE Operating System) does not properly validate Link State Advertisement (LSA) type 1 packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtai
nvd
CVE-2026-17268P3MEDIUMCVSS 6.8≥ 7.3, ≤ 7.6v7.6+3 more2026-08-12
CVE-2026-17268 [MEDIUM] CWE-294 CVE-2026-17268: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrict
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper validation of a session token.
nvd
CVE-2024-22346P3HIGHCVSS 7.8v7.2v7.3+3 more2024-03-14
CVE-2024-22346 [HIGH] CWE-427 CVE-2024-22346: Db2 for IBM i 7.2, 7.3, 7.4, and 7.5 infrastructure could allow a local user to gain elevated privil
Db2 for IBM i 7.2, 7.3, 7.4, and 7.5 infrastructure could allow a local user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privilege. IBM X-Force ID: 280203.
nvd
CVE-2023-30988P3HIGHCVSS 7.8v7.2v7.3+3 more2023-07-16
CVE-2023-30988 [HIGH] CWE-269 CVE-2023-30988: The IBM i 7.2, 7.3, 7.4, and 7.5 product Facsimile Support for i contains a local privilege escalati
The IBM i 7.2, 7.3, 7.4, and 7.5 product Facsimile Support for i contains a local privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain root access to the host operating system. IBM X-Force ID: 254016.
nvd
CVE-2023-40375P3HIGHCVSS 7.8v7.2v7.3+3 more2023-09-28
CVE-2023-40375 [HIGH] CWE-269 CVE-2023-40375: Integrated application server for IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation
Integrated application server for IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain root access to the host operating system. IBM X-Force ID: 263580.
nvd
CVE-2023-40686P3HIGHCVSS 7.8v7.2v7.3+3 more2023-10-29
CVE-2023-40686 [HIGH] CWE-269 CVE-2023-40686: Management Central as part of IBM i 7.2, 7.3, 7.4, and 7.5 Navigator contains a local privilege esca
Management Central as part of IBM i 7.2, 7.3, 7.4, and 7.5 Navigator contains a local privilege escalation vulnerability. A malicious actor with command line access to the operating system can exploit this vulnerability to elevate privileges to gain component access to the operating system. IBM X-Force ID: 264114.
nvd
CVE-2023-40378P3HIGHCVSS 7.8v7.2v7.3+3 more2023-10-15
CVE-2023-40378 [HIGH] CWE-269 CVE-2023-40378: IBM Directory Server for IBM i contains a local privilege escalation vulnerability. A malicious act
IBM Directory Server for IBM i contains a local privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain component access to the host operating system. IBM X-Force ID: 263584.
nvd
CVE-2024-27264P3HIGHCVSS 7.8v7.2v7.3+3 more2024-05-22
CVE-2024-27264 [HIGH] CWE-269 CVE-2024-27264: IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privile
IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privilege. IBM X-Force ID: 284563.
nvd
CVE-2026-1376P3HIGHCVSS 7.5v7.62026-03-17
CVE-2026-1376 [HIGH] CWE-770 CVE-2026-1376: IBM i 7.6 could allow a remote attacker to cause a denial of service using failed authentication con
IBM i 7.6 could allow a remote attacker to cause a denial of service using failed authentication connections due to improper allocation of resources.
nvd
CVE-2026-10852P3HIGHCVSS 7.5v7.3v7.4+2 more2026-06-22
CVE-2026-10852 [HIGH] CWE-476 CVE-2026-10852: IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to deni
IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to denial of service in the WebSphere WebServer Plug-in component when an attacker can pass crafted requests to the web server.
nvd
CVE-2026-17502P3HIGHCVSS 7.5v7.3v7.4+2 more2026-08-13
CVE-2026-17502 [HIGH] CWE-787 CVE-2026-17502: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an ou
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.
nvd
CVE-2023-23470P3HIGHCVSS 7.2v7.2v7.3+3 more2023-05-04
CVE-2023-23470 [HIGH] CWE-89 CVE-2023-23470: IBM i 7.2, 7.3, 7.4, and 7.5 could allow an authenticated privileged administrator to gain elevated
IBM i 7.2, 7.3, 7.4, and 7.5 could allow an authenticated privileged administrator to gain elevated privileges in non-default configurations, as a result of improper SQL processing. By using a specially crafted SQL operation, the administrator could exploit the vulnerability to perform additional administrator operations. IBM X-Force ID: 244510.
nvd
CVE-2026-17445P3MEDIUMCVSS 6.5v7.3v7.4+2 more2026-08-12
CVE-2026-17445 [MEDIUM] CWE-250 CVE-2026-17445: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrict
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper validation of an attacker-supplied user profile name.
nvd
CVE-2026-17420P3MEDIUMCVSS 6.3≥ 7.3, ≤ 7.6v7.6+3 more2026-08-12
CVE-2026-17420 [MEDIUM] CWE-78 CVE-2026-17420: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrict
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper neutralization of special elements in an SQL parameter.
nvd
CVE-2026-17485P3HIGHCVSS 8.2v7.3v7.4+2 more2026-08-12
CVE-2026-17485 [HIGH] CWE-125 CVE-2026-17485: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and obtain s
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and obtain sensitive information due to an integer underflow.
nvd
CVE-2026-17015P3HIGHCVSS 8.1v7.3v7.4+2 more2026-08-19
CVE-2026-17015 [HIGH] CWE-125 CVE-2026-17015: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of servic
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service and obtain sensitive information due to an out-of-bounds read.
nvd