Ibm I vulnerabilities
206 known vulnerabilities affecting ibm/i.
Total CVEs
206
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL21HIGH92MEDIUM87LOW6
Vulnerabilities
Page 7 of 11
CVE-2026-17470P3HIGHCVSS 7.5v7.3v7.4+2 more2026-09-04
CVE-2026-17470 [HIGH] CWE-787 CVE-2026-17470: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a buf
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a buffer overflow.
nvd
CVE-2026-16692P3MEDIUMCVSS 6.5v7.3v7.4+2 more2026-08-13
CVE-2026-16692 [MEDIUM] CWE-787 CVE-2026-16692: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of servic
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a stack-based buffer overflow.
nvd
CVE-2026-16929P3MEDIUMCVSS 6.5v7.3v7.4+2 more2026-08-13
CVE-2026-16929 [MEDIUM] CWE-787 CVE-2026-16929: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive informa
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a buffer overflow.
nvd
CVE-2026-6936P3MEDIUMCVSS 6.5≥ 7.3, ≤ 7.6≥ 7.6, ≤ 11.5.9+3 more2026-05-27
CVE-2026-6936 [MEDIUM] CWE-674 CVE-2026-6936: IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to a denial-of-service attack due to uncontrolled recursio
IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to a denial-of-service attack due to uncontrolled recursion in the Integrated Language Environment (ILE) compiler. An authenticated attacker could exploit this vulnerability by compiling specially crafted source code containing a specific combination of statements.
nvd
CVE-2026-17259P3MEDIUMCVSS 6.5v7.3v7.4+2 more2026-09-04
CVE-2026-17259 [MEDIUM] CWE-121 CVE-2026-17259: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of servic
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a stack-based buffer overflow.
nvd
CVE-2025-36371P3MEDIUMCVSS 6.5v7.2v7.3+3 more2025-11-19
CVE-2025-36371 [MEDIUM] CWE-598 CVE-2025-36371: IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 are impacted by obtaining an information vulnerability in the data
IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 are impacted by obtaining an information vulnerability in the database plan cache implementation. A user with access to the database plan cache could see information they do not have authority to view.
nvd
CVE-2026-18509P3HIGHCVSS 7.1v7.3v7.4+2 more2026-08-13
CVE-2026-18509 [HIGH] CWE-285 CVE-2026-18509: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to gain privilege escalation
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to gain privilege escalation via the Navigator for i debugger. This could allow the attacker to access or manipulate sensitive data on the system, or create new profiles with elevated privileges on the IBM i system.
nvd
CVE-2026-17248P3MEDIUMCVSS 6.5≥ 7.3, ≤ 7.6v7.6+3 more2026-08-12
CVE-2026-17248 [MEDIUM] CWE-78 CVE-2026-17248: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of servic
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to improper neutralization of special elements in an OS command.
nvd
CVE-2026-16878P3MEDIUMCVSS 6.5v7.3v7.4+2 more2026-08-13
CVE-2026-16878 [MEDIUM] CWE-125 CVE-2026-16878: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive informa
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to an out-of-bounds read.
nvd
CVE-2017-1460P4HIGHCVSS 7.5v6.1v7.1+2 more2017-07-31
CVE-2017-1460 [HIGH] CWE-20 CVE-2017-1460: IBM i OSPF 6.1, 7.1, 7.2, and 7.3 is vulnerable when a rogue router spoofs its origin. Routing table
IBM i OSPF 6.1, 7.1, 7.2, and 7.3 is vulnerable when a rogue router spoofs its origin. Routing tables are affected by a missing LSA, which may lead to loss of connectivity. IBM X-Force ID: 128379.
nvd
CVE-2024-52895P4MEDIUMCVSS 6.5v7.4v7.5+2 more2025-02-14
CVE-2024-52895 [MEDIUM] CWE-754 CVE-2024-52895: IBM i 7.4 and 7.5 is vulnerable to a database access denial of service caused by a bypass of a datab
IBM i 7.4 and 7.5 is vulnerable to a database access denial of service caused by a bypass of a database capabilities restriction check. A privileged bad actor can remove or otherwise impact database infrastructure files resulting in incorrect behavior of software products that rely upon the database.
nvd
CVE-2026-18069P4MEDIUMCVSS 6.0v7.6v7.5+2 more2026-09-14
CVE-2026-18069 [MEDIUM] CWE-367 CVE-2026-18069: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to obtain ownership of arbitrary file syst
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to obtain ownership of arbitrary file system objects due to a time-of-check to time-of-use (TOCTOU) race condition.
nvd
CVE-2026-16892P4MEDIUMCVSS 5.4v7.3v7.4+2 more2026-09-04
CVE-2026-16892 [MEDIUM] CWE-287 CVE-2026-16892: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrict
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper authentication during service-name matching.
nvd
CVE-2026-17274P4MEDIUMCVSS 5.4v7.3v7.4+2 more2026-09-04
CVE-2026-17274 [MEDIUM] CWE-330 CVE-2026-17274: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrict
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to predictable server seeds.
nvd
CVE-2026-18065P4MEDIUMCVSS 5.3v7.6v7.5+2 more2026-09-14
CVE-2026-18065 [MEDIUM] CWE-290 CVE-2026-18065: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to gain access to sensiti
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to gain access to sensitive information through session IP binding bypass in Navigator for i.
nvd
CVE-2021-3820P4HIGH≥ 0, < 0.3.72021-09-29
CVE-2021-3820 [HIGH] CWE-1333 inflect vulnerable to Inefficient Regular Expression Complexity
inflect vulnerable to Inefficient Regular Expression Complexity
inflect is customizable inflections for nodejs. inflect is vulnerable to Inefficient Regular Expression Complexity
ghsaosv
CVE-2022-40746P4MEDIUMCVSS 6.7≥ 1.1.2, < 1.1.4≥ 1.1.4.3, < 1.1.9.02022-11-21
CVE-2022-40746 [MEDIUM] CWE-77 CVE-2022-40746: IBM i Access Family 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.0 could allow a local authenticate
IBM i Access Family 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.0 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability. By placing a specially crafted file in a compromised folder, an attacker could exploit this vulnerability to execute arbitrary code on the system. I
nvd
CVE-2026-18099P4MEDIUMCVSS 5.4v7.3v7.4+2 more2026-08-12
CVE-2026-18099 [MEDIUM] CWE-79 CVE-2026-18099: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary script
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary script code due to improper neutralization of user-controlled input.
nvd
CVE-2025-3218P4MEDIUMCVSS 5.4v7.2v7.3+3 more2025-05-07
CVE-2025-3218 [MEDIUM] CWE-295 CVE-2025-3218: IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to authentication and authorization attacks due to i
IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to authentication and authorization attacks due to incorrect validation processing in IBM i Netserver. A malicious actor could use the weaknesses, in conjunction with brute force authentication attacks or to bypass authority restrictions, to access the server.
nvd
CVE-2021-39056P4MEDIUMCVSS 6.5v7.1v7.2+2 more2022-01-13
CVE-2021-39056 [MEDIUM] CVE-2021-39056: The IBM i 7.1, 7.2, 7.3, and 7.4 Extended Dynamic Remote SQL server (EDRSQL) could allow a remote au
The IBM i 7.1, 7.2, 7.3, and 7.4 Extended Dynamic Remote SQL server (EDRSQL) could allow a remote authenticated user to send a specially crafted request and cause a denial of service. IBM X-Force ID: 214537.
nvd