Skip to main content

Vendor/product archive

ibm / i CVEs

Beta · best-effort

152 CVEs tagged to ibm / i6 Critical, 62 High, 78 Medium, 6 Low, 0 Unrated.

CVE-2024-31879

Published May 18, 2024

IBM i 7.2, 7.3, and 7.4 could allow a remote attacker to execute arbitrary code leading to a denial of service of network ports on the system, caused by the deserialization of unt…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-25050

Published Apr 28, 2024

IBM i 7.2, 7.3, 7.4, 7.5 and IBM Rational Development Studio for i 7.2, 7.3, 7.4, 7.5 networking and compiler infrastructure could allow a local user to gain elevated privileges d…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-22346

Published Mar 14, 2024

Db2 for IBM i 7.2, 7.3, 7.4, and 7.5 infrastructure could allow a local user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-con…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-43064

Published Dec 25, 2023

Facsimile Support for IBM i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqualified library call. A malicious actor could cause arbitrar…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2023-47741

Published Dec 18, 2023

IBM i 7.3, 7.4, 7.5, IBM i Db2 Mirror for i 7.4 and 7.5 web browser clients may leave clear-text passwords in browser memory that can be viewed using common browser tools before t…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-42006

Published Dec 1, 2023

IBM Administration Runtime Expert for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to obtain sensitive information caused by improper authority checks. IBM X-Force ID: 2652…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-40685

Published Oct 29, 2023

Management Central as part of IBM i 7.2, 7.3, 7.4, and 7.5 Navigator contains a local privilege escalation vulnerability. A malicious actor with command line access to the operat…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-40686

Published Oct 29, 2023

Management Central as part of IBM i 7.2, 7.3, 7.4, and 7.5 Navigator contains a local privilege escalation vulnerability. A malicious actor with command line access to the operat…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-40377

Published Oct 16, 2023

Backup, Recovery, and Media Services (BRMS) for IBM i 7.2, 7.3, and 7.4 contains a local privilege escalation vulnerability. A malicious actor with command line access to the hos…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-40378

Published Oct 15, 2023

IBM Directory Server for IBM i contains a local privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-40375

Published Sep 28, 2023

Integrated application server for IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability. A malicious actor with command line access to the host operati…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-38721

Published Aug 14, 2023

The IBM i 7.2, 7.3, 7.4, and 7.5 product Facsimile Support for i contains a local privilege escalation vulnerability. A malicious actor could gain access to a command line with…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-30989

Published Jul 16, 2023

IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability. A malicious actor with command line access to the host operating system ca…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-30988

Published Jul 16, 2023

The IBM i 7.2, 7.3, 7.4, and 7.5 product Facsimile Support for i contains a local privilege escalation vulnerability. A malicious actor with command line access to the host opera…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-30990

Published Jul 4, 2023

IBM i 7.2, 7.3, 7.4, and 7.5 could allow a remote attacker to execute CL commands as QUSER, caused by an exploitation of DDM architecture. IBM X-Force ID: 254036.

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-23470

Published May 4, 2023

IBM i 7.2, 7.3, 7.4, and 7.5 could allow an authenticated privileged administrator to gain elevated privileges in non-default configurations, as a result of improper SQL processin…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 76-100 of 152 CVEsPage 4 of 7