Ibm I Access Client Solutions vulnerabilities
12 known vulnerabilities affecting ibm/i_access_client_solutions.
Total CVEs
12
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH8MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2026-7770P2HIGHCVSS 8.8≥ 1.1.5.0, < 1.1.9.132026-06-01
CVE-2026-7770 [HIGH] CWE-74 CVE-2026-7770: IBM i Access Family 1.1.5.0 through 1.1.9.12 IBM i Access Client Solutions (ACS) is vulnerable to re
IBM i Access Family 1.1.5.0 through 1.1.9.12 IBM i Access Client Solutions (ACS) is vulnerable to remote code execution when configured to listen for requests from IBM i Navigator.
nvd
CVE-2026-13433P3CRITICALCVSS 9.6≥ 1.1.2, < 1.1.9.14≥ 1.1.2.0, ≤ 1.1.9.132026-08-12
CVE-2026-13433 [CRITICAL] CWE-494 CVE-2026-13433: IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to downloading unverified
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to downloading unverified product code when configured to update from an IBM i. A bad actor could use this vulnerablity to run compromised code on the ACS user's workstation.
nvd
CVE-2023-45185P3HIGHCVSS 8.8≥ 1.1.2, ≤ 1.1.4≥ 1.1.4.3, < 1.1.9.4+1 more2023-12-14
CVE-2023-45185 [HIGH] CWE-863 CVE-2023-45185: IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an attacke
IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an attacker to execute remote code. Due to improper authority checks the attacker could perform operations on the PC under the user's authority. IBM X-Force ID: 268273.
nvd
CVE-2024-22318P4MEDIUMCVSS 5.5PoC≥ 1.1.2, ≤ 1.1.4≥ 1.1.4.3, ≤ 1.1.9.42024-02-09
CVE-2024-22318 [MEDIUM] CWE-327 CVE-2024-22318: IBM i Access Client Solutions (ACS) 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.4 is vulnerable to
IBM i Access Client Solutions (ACS) 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.4 is vulnerable to NT LAN Manager (NTLM) hash disclosure by an attacker modifying UNC capable paths within ACS configuration files to point to a hostile server. If NTLM is enabled, the Windows operating system will try to authenticate using the current user's session.
nvd
CVE-2026-13105P3HIGHCVSS 8.8≥ 1.1.2, < 1.1.9.14≥ 1.1.2.0, ≤ 1.1.9.132026-08-12
CVE-2026-13105 [HIGH] CWE-22 CVE-2026-13105: IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to zip slip path traversal expl
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to zip slip path traversal exploit when importing a configuration.
nvd
CVE-2026-13094P3HIGHCVSS 7.8≥ 1.1.2, < 1.1.9.14≥ 1.1.2.0, ≤ 1.1.9.132026-08-12
CVE-2026-13094 [HIGH] CWE-94 CVE-2026-13094: IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when installed for all users due to publicly writeable configuration file.
nvd
CVE-2026-14875P3HIGHCVSS 7.8≥ 1.1.2, < 1.1.9.14≥ 1.1.2.0, ≤ 1.1.9.132026-08-13
CVE-2026-14875 [HIGH] CWE-426 CVE-2026-14875: IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when installed for all users due to publicly writeable directory.
nvd
CVE-2026-16695P3HIGHCVSS 7.8≥ 1.1.2, < 1.1.9.14≥ 1.1.2.0, ≤ 1.1.9.132026-08-12
CVE-2026-16695 [HIGH] CWE-78 CVE-2026-16695: IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 could allow a local attacker to execute arbit
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 could allow a local attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
nvd
CVE-2023-45184P3HIGHCVSS 7.5≥ 1.1.2, ≤ 1.1.4≥ 1.1.4.3, < 1.1.9.4+1 more2023-12-14
CVE-2023-45184 [HIGH] CWE-922 CVE-2023-45184: IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an attacke
IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an attacker to obtain a decryption key due to improper authority checks. IBM X-Force ID: 268270.
nvd
CVE-2026-14866P3HIGHCVSS 7.1≥ 1.1.2, < 1.1.9.14≥ 1.1.2.0, ≤ 1.1.9.132026-08-12
CVE-2026-14866 [HIGH] CWE-798 CVE-2026-14866: IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to injection of rogue certifica
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to injection of rogue certificate authority due to publicly writeable truststore.
nvd
CVE-2022-40746P4MEDIUMCVSS 6.7≥ 1.1.2, ≤ 1.1.4≥ 1.1.4.3, ≤ 1.1.9.02022-11-21
CVE-2022-40746 [MEDIUM] CWE-77 CVE-2022-40746: IBM i Access Family 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.0 could allow a local authenticate
IBM i Access Family 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.0 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability. By placing a specially crafted file in a compromised folder, an attacker could exploit this vulnerability to execute arbitrary code on the system. I
nvd
CVE-2023-45182P4MEDIUMCVSS 6.5≥ 1.1.2, ≤ 1.1.4≥ 1.1.4.3, < 1.1.9.4+1 more2023-12-14
CVE-2023-45182 [MEDIUM] CWE-922 CVE-2023-45182: IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 is vulnerable to havi
IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 is vulnerable to having its key for an encrypted password decoded. By somehow gaining access to the encrypted password, a local attacker could exploit this vulnerability to obtain the password to other systems. IBM X-Force ID: 268265.
nvd