CVE-2022-43857
- EPSS 0.31%
- Veröffentlicht 22.12.2022 21:15:10
- Zuletzt bearbeitet 21.11.2024 07:27:16
IBM Navigator for i 7.3, 7.4 and 7.5 could allow an authenticated user to access IBM Navigator for i log files they are authorized to but not while using this interface. The remote authenticated user can bypass the interface checks and download log...
CVE-2022-34358
- EPSS 0.24%
- Veröffentlicht 13.07.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 07:09:21
IBM i 7.2, 7.3, 7.4, and 7.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trust...
CVE-2022-22495
- EPSS 0.22%
- Veröffentlicht 24.05.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:46:54
IBM i 7.3, 7.4, and 7.5 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 226941.
CVE-2022-22481
- EPSS 0.17%
- Veröffentlicht 09.05.2022 17:15:09
- Zuletzt bearbeitet 21.11.2024 06:46:52
IBM Navigator for i 7.2, 7.3, and 7.4 (heritage version) could allow a remote attacker to obtain access to the web interface without valid credentials. By modifying the sign on request, an attacker can gain visibility to the fully qualified domain na...
CVE-2021-39056
- EPSS 0.28%
- Veröffentlicht 13.01.2022 18:15:07
- Zuletzt bearbeitet 21.11.2024 06:18:30
The IBM i 7.1, 7.2, 7.3, and 7.4 Extended Dynamic Remote SQL server (EDRSQL) could allow a remote authenticated user to send a specially crafted request and cause a denial of service. IBM X-Force ID: 214537.
CVE-2021-38876
- EPSS 0.17%
- Veröffentlicht 30.12.2021 17:15:12
- Zuletzt bearbeitet 21.11.2024 06:18:08
IBM i 7.2, 7.3, and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted se...
CVE-2021-20501
- EPSS 0.45%
- Veröffentlicht 21.04.2021 12:15:08
- Zuletzt bearbeitet 21.11.2024 05:46:40
IBM i 7.1, 7.2, 7.3, and 7.4 SMTP allows a network attacker to send emails to non-existent local-domain recipients to the SMTP server, caused by using a non-default configuration. An attacker could exploit this vulnerability to consume unnecessary ne...
CVE-2020-4345
- EPSS 0.05%
- Veröffentlicht 17.05.2020 14:15:10
- Zuletzt bearbeitet 21.11.2024 05:32:37
IBM i 7.2, 7.3, and 7.4 users running complex SQL statements under a specific set of circumstances may allow a local user to obtain sensitive information that they should not have access to. IBM X-Force ID: 178318.
CVE-2019-4450
- EPSS 0.28%
- Veröffentlicht 09.11.2019 02:15:10
- Zuletzt bearbeitet 21.11.2024 04:43:37
IBM i 7.2, 7.3, and 7.4 for i is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trus...
CVE-2019-4536
- EPSS 0.04%
- Veröffentlicht 29.08.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:43:41
IBM i 7.4 users who have done a Restore User Profile (RSTUSRPRF) on a system which has been configured with Db2 Mirror for i might have user profiles with elevated privileges caused by incorrect processing during a restore of multiple user profiles. ...