cbcvebase.

Ibm I vulnerabilities

206 known vulnerabilities affecting ibm/i.

Total CVEs
206
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL21HIGH92MEDIUM87LOW6

Vulnerabilities

Page 6 of 11
CVE-2023-38721P3HIGHCVSS 7.8v7.2v7.3+3 more2023-08-14
CVE-2023-38721 [HIGH] CWE-269 CVE-2023-38721: The IBM i 7.2, 7.3, 7.4, and 7.5 product Facsimile Support for i contains a local privilege escalati The IBM i 7.2, 7.3, 7.4, and 7.5 product Facsimile Support for i contains a local privilege escalation vulnerability. A malicious actor could gain access to a command line with elevated privileges allowing root access to the host operating system. IBM X-Force ID: 262173.
nvd
CVE-2023-30989P3HIGHCVSS 7.8v7.2v7.3+3 more2023-07-16
CVE-2023-30989 [HIGH] CWE-269 CVE-2023-30989: IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerabili IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain all object access to the host operating system. IBM X-Force ID: 254017.
nvd
CVE-2023-40377P3HIGHCVSS 7.8v7.2v7.3+2 more2023-10-16
CVE-2023-40377 [HIGH] CWE-269 CVE-2023-40377: Backup, Recovery, and Media Services (BRMS) for IBM i 7.2, 7.3, and 7.4 contains a local privilege e Backup, Recovery, and Media Services (BRMS) for IBM i 7.2, 7.3, and 7.4 contains a local privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain component access to the host operating system. IBM X-Force ID: 263583.
nvd
CVE-2026-17094P3HIGHCVSS 7.1v7.3v7.4+2 more2026-08-12
CVE-2026-17094 [HIGH] CWE-22 CVE-2026-17094: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive informa IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and manipulate files due to a path traversal vulnerability.
nvd
CVE-2026-18869P3MEDIUMCVSS 6.4v7.6v7.5+2 more2026-09-18
CVE-2026-18869 [MEDIUM] CWE-918 CVE-2026-18869: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrict IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions and access internal network services due to improper validation of FTP PORT and EPRT commands.
nvd
CVE-2026-17199P3HIGHCVSS 7.5≥ 7.3, ≤ 7.6v7.6+3 more2026-08-13
CVE-2026-17199 [HIGH] CWE-770 CVE-2026-17199: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to unbou IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to unbounded resource allocation.
nvd
CVE-2026-16931P3HIGHCVSS 7.5≥ 7.3, ≤ 7.6v7.6+3 more2026-08-12
CVE-2026-16931 [HIGH] CWE-835 CVE-2026-16931: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to impro IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper handling of zero-length TCP options.
nvd
CVE-2026-17271P3HIGHCVSS 7.5≥ 7.3, ≤ 7.6v7.6+3 more2026-08-12
CVE-2026-17271 [HIGH] CWE-770 CVE-2026-17271: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to impro IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of input size.
nvd
CVE-2026-16982P3HIGHCVSS 7.5v7.3v7.4+2 more2026-08-13
CVE-2026-16982 [HIGH] CWE-787 CVE-2026-16982: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a hea IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a heap buffer overflow.
nvd
CVE-2026-16868P3HIGHCVSS 7.5v7.3v7.4+2 more2026-08-13
CVE-2026-16868 [HIGH] CWE-908 CVE-2026-16868: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to the u IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to the use of uninitialized memory during ASN.1 length processing.
nvd
CVE-2026-17255P3HIGHCVSS 7.5v7.3v7.4+2 more2026-09-04
CVE-2026-17255 [HIGH] CWE-787 CVE-2026-17255: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to impro IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of the prefix length in ICMPv6 Router Advertisements.
nvd
CVE-2024-38330P3HIGHCVSS 7.8v7.2v7.3+2 more2024-07-08
CVE-2024-38330 [HIGH] CWE-427 CVE-2024-38330: IBM System Management for i 7.2, 7.3, and 7.4 could allow a local user to gain elevated privileges d IBM System Management for i 7.2, 7.3, and 7.4 could allow a local user to gain elevated privileges due to an unqualified library program call. A malicious actor could cause user-controlled code to run with administrator privilege. IBM X-Force ID: 295227.
nvd
CVE-2024-27275P3HIGHCVSS 7.8v7.2v7.3+2 more2024-06-15
CVE-2024-27275 [HIGH] CWE-266 CVE-2024-27275: IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability caused by an insuff IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability caused by an insufficient authority requirement. A local user without administrator privilege can configure a physical file trigger to execute with the privileges of a user socially engineered to access the target file. The correction is to require administrator privilege
nvd
CVE-2026-17004P3HIGHCVSS 7.5v7.3v7.4+2 more2026-08-13
CVE-2026-17004 [HIGH] CWE-835 CVE-2026-17004: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an in IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an infinite loop.
nvd
CVE-2026-17229P3HIGHCVSS 7.5≥ 7.3, ≤ 7.6v7.6+3 more2026-08-13
CVE-2026-17229 [HIGH] CWE-835 CVE-2026-17229: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an in IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an infinite loop.
nvd
CVE-2024-47104P3MEDIUMCVSS 6.8v7.4v7.5+1 more2024-12-18
CVE-2024-47104 [MEDIUM] CWE-732 CVE-2024-47104: IBM i 7.4 and 7.5 is vulnerable to an authenticated user gaining elevated privilege to a physical fi IBM i 7.4 and 7.5 is vulnerable to an authenticated user gaining elevated privilege to a physical file. A user with authority to a view can alter the based-on physical file security attributes without having object management rights to the physical file. A malicious actor can use the elevated privileges to perform actions restricted by their view pr
nvd
CVE-2026-17266P3MEDIUMCVSS 6.5≥ 7.3, ≤ 7.6v7.6+3 more2026-08-12
CVE-2026-17266 [MEDIUM] CWE-22 CVE-2026-17266: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive informa IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.
nvd
CVE-2026-18715P3MEDIUMCVSS 6.5v7.3v7.4+2 more2026-08-13
CVE-2026-18715 [MEDIUM] CWE-611 CVE-2026-18715: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive informa IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper processing of XML external entities.
nvd
CVE-2026-18887P3MEDIUMCVSS 6.5v7.3v7.4+2 more2026-09-04
CVE-2026-18887 [MEDIUM] CWE-200 CVE-2026-18887: IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to obtain sensitive information i IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to obtain sensitive information in PASE. An attacker could exploit this vulnerability to access information about process they shouldn't be permitted to access.
nvd
CVE-2026-17272P3HIGHCVSS 7.5v7.3v7.4+2 more2026-08-13
CVE-2026-17272 [HIGH] CWE-787 CVE-2026-17272: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a buf IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a buffer overflow.
nvd
Ibm I vulnerabilities | cvebase