CVE-2026-1376
- EPSS 0.07%
- Veröffentlicht 17.03.2026 21:53:44
- Zuletzt bearbeitet 19.03.2026 14:40:00
IBM i 7.6 could allow a remote attacker to cause a denial of service using failed authentication connections due to improper allocation of resources.
CVE-2025-36371
- EPSS 0.05%
- Veröffentlicht 19.11.2025 19:45:31
- Zuletzt bearbeitet 24.11.2025 14:57:26
IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 are impacted by obtaining an information vulnerability in the database plan cache implementation. A user with access to the database plan cache could see information they do not have authority to view.
CVE-2025-36367
- EPSS 0.08%
- Veröffentlicht 01.11.2025 12:15:35
- Zuletzt bearbeitet 05.11.2025 19:03:58
IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 is vulnerable to privilege escalation caused by an invalid IBM i SQL services authorization check. A malicious actor can use the elevated privileges of another user profile to gain root access to the host operating s...
CVE-2025-36119
- EPSS 0.02%
- Veröffentlicht 08.08.2025 14:25:40
- Zuletzt bearbeitet 15.08.2025 18:15:27
IBM i 7.3, 7.4, 7.5, and 7.6 is affected by an authenticated user obtaining elevated privileges with IBM Digital Certificate Manager for i (DCM) due to a web session hijacking vulnerability. An authenticated user without administrator privileges coul...
CVE-2025-33109
- EPSS 0.04%
- Veröffentlicht 24.07.2025 15:06:49
- Zuletzt bearbeitet 11.08.2025 18:57:22
IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to a privilege escalation caused by an invalid database authority check. A bad actor could execute a database procedure or function without having all required permissions, in addition to causing denia...
CVE-2025-36004
- EPSS 0.08%
- Veröffentlicht 25.06.2025 02:32:40
- Zuletzt bearbeitet 03.07.2025 20:53:35
IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user to gain elevated privileges due to an unqualified library call in IBM Facsimile Support for i. A malicious actor could cause user-controlled code to run with administrator privilege.
CVE-2025-33122
- EPSS 0.06%
- Veröffentlicht 17.06.2025 17:13:00
- Zuletzt bearbeitet 03.07.2025 20:53:32
IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 could allow a user to gain elevated privileges due to an unqualified library call in IBM Advanced Job Scheduler for i. A malicious actor could cause user-controlled code to run with administrator privilege.
CVE-2025-33108
- EPSS 0.06%
- Veröffentlicht 14.06.2025 00:25:23
- Zuletzt bearbeitet 20.08.2025 17:16:50
IBM Backup, Recovery and Media Services for i 7.4 and 7.5 could allow a user with the capability to compile or restore a program to gain elevated privileges due to a library unqualified call made by a BRMS program. A malicious actor could cause use...
CVE-2025-33103
- EPSS 0.18%
- Veröffentlicht 17.05.2025 16:15:18
- Zuletzt bearbeitet 04.06.2025 20:12:06
IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 product IBM TCP/IP Connectivity Utilities for i contains a privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain root access to the...
CVE-2025-3218
- EPSS 0.1%
- Veröffentlicht 07.05.2025 01:10:57
- Zuletzt bearbeitet 03.07.2025 20:53:29
IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to authentication and authorization attacks due to incorrect validation processing in IBM i Netserver. A malicious actor could use the weaknesses, in conjunction with brute force authentication attacks...