Ibm I vulnerabilities
206 known vulnerabilities affecting ibm/i.
Total CVEs
206
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL21HIGH92MEDIUM87LOW6
Vulnerabilities
Page 9 of 11
CVE-2024-31878P4MEDIUMCVSS 5.3v7.2v7.3+3 more2024-06-07
CVE-2024-31878 [MEDIUM] CWE-203 CVE-2024-31878: IBM i 7.2, 7.3, 7.4, and 7.5 Service Tools Server (SST) is vulnerable to SST user enumeration by a r
IBM i 7.2, 7.3, 7.4, and 7.5 Service Tools Server (SST) is vulnerable to SST user enumeration by a remote attacker. This vulnerability can be used by a malicious actor to gather information about SST users that can be targeted in further attacks. IBM X-Force ID: 287538.
nvd
CVE-2026-17476P4MEDIUMCVSS 5.3v7.3v7.4+2 more2026-08-13
CVE-2026-17476 [MEDIUM] CWE-787 CVE-2026-17476: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an im
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an improper buffer write.
nvd
CVE-2026-18086P4MEDIUMCVSS 5.3v7.3v7.4+2 more2026-08-13
CVE-2026-18086 [MEDIUM] CWE-787 CVE-2026-18086: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code or cause a denia
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code or cause a denial of service due to improper bounds checking.
nvd
CVE-2026-17109P4MEDIUMCVSS 4.3≥ 7.3, ≤ 7.6v7.6+3 more2026-08-12
CVE-2026-17109 [MEDIUM] CWE-20 CVE-2026-17109: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to add unexpected parameter
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to add unexpected parameters to a command due to parameter injection.
nvd
CVE-2019-4040P4MEDIUMCVSS 6.1v7.2v7.32019-01-31
CVE-2019-4040 [MEDIUM] CWE-79 CVE-2019-4040: IBM I 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed ar
IBM I 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 156164.
nvd
CVE-2021-38876P4MEDIUMCVSS 6.1v7.2v7.3+1 more2021-12-30
CVE-2021-38876 [MEDIUM] CWE-79 CVE-2021-38876: IBM i 7.2, 7.3, and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to em
IBM i 7.2, 7.3, and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 208404.
nvd
CVE-2026-17226P4MEDIUMCVSS 5.4v7.3v7.4+2 more2026-08-13
CVE-2026-17226 [MEDIUM] CWE-125 CVE-2026-17226: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive informa
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information or cause a denial of service due to an out-of-bounds read.
nvd
CVE-2026-17216P4MEDIUMCVSS 5.3v7.3v7.4+2 more2026-08-13
CVE-2026-17216 [MEDIUM] CWE-190 CVE-2026-17216: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an in
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an integer error when processing DRDA large-object headers.
nvd
CVE-2026-18148P4MEDIUMCVSS 4.3v7.3v7.4+2 more2026-08-12
CVE-2026-18148 [MEDIUM] CWE-117 CVE-2026-18148: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to inject arbitrary content
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to inject arbitrary content into Navigator log files due to improper output neutralization for logs.
nvd
CVE-2026-18246P4MEDIUMCVSS 4.3v7.3v7.4+2 more2026-08-12
CVE-2026-18246 [MEDIUM] CWE-436 CVE-2026-18246: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrict
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to an interpretation conflict in the multipart parser.
nvd
CVE-2026-18515P4MEDIUMCVSS 4.3v7.6v7.5+2 more2026-09-14
CVE-2026-18515 [MEDIUM] CWE-22 CVE-2026-18515: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to place files into the fil
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to place files into the file system with Navigator for i when they should be blocked by Navigator configuration. This could allow attackers to upload files onto the system to places the Navigator support did not intend, but only if the profile could already do that by itself.
nvd
CVE-2019-4450P4MEDIUMCVSS 6.1v7.2v7.3+1 more2019-11-09
CVE-2019-4450 [MEDIUM] CWE-79 CVE-2019-4450: IBM i 7.2, 7.3, and 7.4 for i is vulnerable to cross-site scripting. This vulnerability allows users
IBM i 7.2, 7.3, and 7.4 for i is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 163492.
nvd
CVE-2019-4381P4MEDIUMCVSS 5.5v7.2v7.3+1 more2019-06-14
CVE-2019-4381 [MEDIUM] CWE-255 CVE-2019-4381: IBM i 7.27.3 Clustering could allow a local attacker to obtain sensitive information, caused by the
IBM i 7.27.3 Clustering could allow a local attacker to obtain sensitive information, caused by the use of advanced node failure detection using the REST API to interface with the HMC. An attacker could exploit this vulnerability to obtain HMC credentials. IBM X-Force ID: 162159.
nvd
CVE-2022-34358P4MEDIUMCVSS 5.4v7.2v7.3+2 more2022-07-13
CVE-2022-34358 [MEDIUM] CWE-79 CVE-2022-34358: IBM i 7.2, 7.3, 7.4, and 7.5 is vulnerable to cross-site scripting. This vulnerability allows users
IBM i 7.2, 7.3, 7.4, and 7.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 230516.
nvd
CVE-2026-17270P4MEDIUMCVSS 5.5v7.3v7.4+2 more2026-09-04
CVE-2026-17270 [MEDIUM] CWE-121 CVE-2026-17270: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to a stac
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to a stack-based buffer overflow.
nvd
CVE-2026-18858P4MEDIUMCVSS 5.5v7.5v7.62026-09-04
CVE-2026-18858 [MEDIUM] CWE-267 CVE-2026-18858: IBM i 7.6, and 7.5 could allow a local authenticated attacker to obtain information from a privilege
IBM i 7.6, and 7.5 could allow a local authenticated attacker to obtain information from a privileged file when using SSH.
nvd
CVE-2026-16693P4MEDIUMCVSS 4.9v7.3v7.4+2 more2026-09-04
CVE-2026-16693 [MEDIUM] CWE-327 CVE-2026-16693: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive informa
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to the use of hardcoded cryptographic constants to obfuscate encryption keys.
nvd
CVE-2026-18144P4MEDIUMCVSS 4.3v7.3v7.4+2 more2026-08-12
CVE-2026-18144 [MEDIUM] CWE-285 CVE-2026-18144: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrict
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.
nvd
CVE-2026-17074P4MEDIUMCVSS 4.3v7.3v7.4+2 more2026-08-13
CVE-2026-17074 [MEDIUM] CWE-269 CVE-2026-17074: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrict
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper privilege management.
nvd
CVE-2022-43860P4MEDIUMCVSS 4.3v7.3v7.4+1 more2022-12-24
CVE-2022-43860 [MEDIUM] CWE-89 CVE-2022-43860: IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive informat
IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information they are authorized to but not while using this interface. By performing an SQL injection an attacker could see user profile attributes through this interface. IBM X-Force ID: 239305.
nvd