Ibm I vulnerabilities
206 known vulnerabilities affecting ibm/i.
Total CVEs
206
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL21HIGH92MEDIUM87LOW6
Vulnerabilities
Page 8 of 11
CVE-2026-17273P4MEDIUMCVSS 6.5v7.3v7.4+2 more2026-09-04
CVE-2026-17273 [MEDIUM] CWE-476 CVE-2026-17273: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of servic
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a NULL pointer dereference.
nvd
CVE-2026-18076P4MEDIUMCVSS 6.5v7.3v7.4+2 more2026-09-04
CVE-2026-18076 [MEDIUM] CWE-401 CVE-2026-18076: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of servic
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a memory leak.
nvd
CVE-2022-22481P4MEDIUMCVSS 5.3v7.2v7.3+1 more2022-05-09
CVE-2022-22481 [MEDIUM] CVE-2022-22481: IBM Navigator for i 7.2, 7.3, and 7.4 (heritage version) could allow a remote attacker to obtain acc
IBM Navigator for i 7.2, 7.3, and 7.4 (heritage version) could allow a remote attacker to obtain access to the web interface without valid credentials. By modifying the sign on request, an attacker can gain visibility to the fully qualified domain name of the target system and the navigator tasks page, however they do not gain the ability to perform those t
nvd
CVE-2026-18078P4MEDIUMCVSS 6.5v7.3v7.4+2 more2026-09-04
CVE-2026-18078 [MEDIUM] CWE-190 CVE-2026-18078: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of servic
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to an integer overflow.
nvd
CVE-2019-4536P4MEDIUMCVSS 6.3v7.42019-08-29
CVE-2019-4536 [MEDIUM] CWE-269 CVE-2019-4536: IBM i 7.4 users who have done a Restore User Profile (RSTUSRPRF) on a system which has been configur
IBM i 7.4 users who have done a Restore User Profile (RSTUSRPRF) on a system which has been configured with Db2 Mirror for i might have user profiles with elevated privileges caused by incorrect processing during a restore of multiple user profiles. A user with restore privileges could exploit this vulnerability to obtain elevated privileges on the re
nvd
CVE-2026-18150P4MEDIUMCVSS 5.3v7.3v7.4+2 more2026-08-12
CVE-2026-18150 [MEDIUM] CWE-362 CVE-2026-18150: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive informa
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a race condition.
nvd
CVE-2025-2950P4MEDIUMCVSS 5.4v7.3v7.4+2 more2025-04-18
CVE-2025-2950 [MEDIUM] CWE-644 CVE-2025-2950: IBM i 7.3, 7.4, 7.5, and 7.5 is vulnerable to a host header injection attack caused by improper neut
IBM i 7.3, 7.4, 7.5, and 7.5 is vulnerable to a host header injection attack caused by improper neutralization of HTTP header content by IBM Navigator for i. An authenticated user can manipulate the host header in HTTP requests to change domain/IP address which may lead to unexpected behavior.
nvd
CVE-2026-17649P4MEDIUMCVSS 5.3v7.3v7.4+2 more2026-08-13
CVE-2026-17649 [MEDIUM] CWE-125 CVE-2026-17649: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.
nvd
CVE-2026-16859P4MEDIUMCVSS 5.3v7.3v7.4+2 more2026-08-13
CVE-2026-16859 [MEDIUM] CWE-125 CVE-2026-16859: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.
nvd
CVE-2026-18671P4MEDIUMCVSS 5.3v7.3v7.4+2 more2026-08-13
CVE-2026-18671 [MEDIUM] CWE-190 CVE-2026-18671: IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to force a NetServer server threa
IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to force a NetServer server thread exception, caused by an integer overflow during bounds checking in request processing. The attacker could exploit this vulnerability to cause a temporary denial of service.
nvd
CVE-2026-17077P4MEDIUMCVSS 5.3v7.3v7.4+2 more2026-08-13
CVE-2026-17077 [MEDIUM] CWE-457 CVE-2026-17077: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to the u
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to the use of an uninitialized variable.
nvd
CVE-2026-17212P4MEDIUMCVSS 5.3v7.3v7.4+2 more2026-08-13
CVE-2026-17212 [MEDIUM] CWE-125 CVE-2026-17212: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an ou
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.
nvd
CVE-2026-16861P4MEDIUMCVSS 5.3v7.3v7.4+2 more2026-08-13
CVE-2026-16861 [MEDIUM] CWE-125 CVE-2026-16861: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an ou
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.
nvd
CVE-2026-18250P4MEDIUMCVSS 5.0≥ 7.3, ≤ 7.6v7.6+3 more2026-08-12
CVE-2026-18250 [MEDIUM] CWE-362 CVE-2026-18250: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive informa
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to a race condition.
nvd
CVE-2026-17222P4MEDIUMCVSS 4.3≥ 7.3, ≤ 7.6v7.6+3 more2026-08-12
CVE-2026-17222 [MEDIUM] CWE-89 CVE-2026-17222: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to modify data in certain S
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to modify data in certain SQL tables due to improper neutralization of special elements used in an SQL command.
nvd
CVE-2026-17078P4MEDIUMCVSS 5.3v7.3v7.4+2 more2026-08-13
CVE-2026-17078 [MEDIUM] CWE-400 CVE-2026-17078: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to resou
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to resource exhaustion.
nvd
CVE-2026-17076P4MEDIUMCVSS 5.3v7.3v7.4+2 more2026-08-13
CVE-2026-17076 [MEDIUM] CWE-770 CVE-2026-17076: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to impro
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper processing of DRDA and DDM resynchronization requests.
nvd
CVE-2026-18020P4MEDIUMCVSS 5.3v7.3v7.4+2 more2026-08-13
CVE-2026-18020 [MEDIUM] CWE-125 CVE-2026-18020: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an of
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an off-by-one error in bounds checking.
nvd
CVE-2026-16694P4MEDIUMCVSS 5.4v7.3v7.4+2 more2026-08-12
CVE-2026-16694 [MEDIUM] CWE-79 CVE-2026-16694: IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to stored cross-site scripting. This vulnerability allows
IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2024-55896P4MEDIUMCVSS 5.4v7.4v7.5+1 more2025-01-03
CVE-2024-55896 [MEDIUM] CWE-451 CVE-2024-55896: IBM PowerHA SystemMirror for i 7.4 and 7.5 contains improper restrictions when rendering content via
IBM PowerHA SystemMirror for i 7.4 and 7.5 contains improper restrictions when rendering content via iFrames. This vulnerability could allow an attacker to gain improper access and perform unauthorized actions on the system.
nvd