CVE-2021-39056
- EPSS 0.28%
- Published 13.01.2022 18:15:07
- Last modified 21.11.2024 06:18:30
The IBM i 7.1, 7.2, 7.3, and 7.4 Extended Dynamic Remote SQL server (EDRSQL) could allow a remote authenticated user to send a specially crafted request and cause a denial of service. IBM X-Force ID: 214537.
CVE-2021-38876
- EPSS 0.23%
- Published 30.12.2021 17:15:12
- Last modified 21.11.2024 06:18:08
IBM i 7.2, 7.3, and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted se...
CVE-2021-20501
- EPSS 0.45%
- Published 21.04.2021 12:15:08
- Last modified 21.11.2024 05:46:40
IBM i 7.1, 7.2, 7.3, and 7.4 SMTP allows a network attacker to send emails to non-existent local-domain recipients to the SMTP server, caused by using a non-default configuration. An attacker could exploit this vulnerability to consume unnecessary ne...
CVE-2020-4345
- EPSS 0.05%
- Published 17.05.2020 14:15:10
- Last modified 21.11.2024 05:32:37
IBM i 7.2, 7.3, and 7.4 users running complex SQL statements under a specific set of circumstances may allow a local user to obtain sensitive information that they should not have access to. IBM X-Force ID: 178318.
CVE-2019-4450
- EPSS 0.33%
- Published 09.11.2019 02:15:10
- Last modified 21.11.2024 04:43:37
IBM i 7.2, 7.3, and 7.4 for i is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trus...
CVE-2019-4536
- EPSS 0.04%
- Published 29.08.2019 15:15:11
- Last modified 21.11.2024 04:43:41
IBM i 7.4 users who have done a Restore User Profile (RSTUSRPRF) on a system which has been configured with Db2 Mirror for i might have user profiles with elevated privileges caused by incorrect processing during a restore of multiple user profiles. ...
CVE-2019-4381
- EPSS 0.05%
- Published 14.06.2019 15:29:00
- Last modified 21.11.2024 04:43:31
IBM i 7.27.3 Clustering could allow a local attacker to obtain sensitive information, caused by the use of advanced node failure detection using the REST API to interface with the HMC. An attacker could exploit this vulnerability to obtain HMC creden...
CVE-2019-4040
- EPSS 0.24%
- Published 31.01.2019 15:29:00
- Last modified 21.11.2024 04:43:04
IBM I 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session....
CVE-2017-1460
- EPSS 0.39%
- Published 31.07.2017 21:29:00
- Last modified 20.04.2025 01:37:25
IBM i OSPF 6.1, 7.1, 7.2, and 7.3 is vulnerable when a rogue router spoofs its origin. Routing tables are affected by a missing LSA, which may lead to loss of connectivity. IBM X-Force ID: 128379.
CVE-2013-5385
- EPSS 5.54%
- Published 02.01.2014 14:59:03
- Last modified 11.04.2025 00:51:21
The OSPF implementation in IBM i 6.1 and 7.1, in z/OS on zSeries servers, and in Networking Operating System (aka NOS, formerly BLADE Operating System) does not properly validate Link State Advertisement (LSA) type 1 packets before performing operati...