CVE-2026-16694
- EPSS 0.17%
- Veröffentlicht 12.08.2026 16:59:17
- Zuletzt bearbeitet 17.08.2026 14:27:44
IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials di...
CVE-2026-17094
- EPSS 0.4%
- Veröffentlicht 12.08.2026 16:57:46
- Zuletzt bearbeitet 17.08.2026 14:20:21
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and manipulate files due to a path traversal vulnerability.
CVE-2026-17095
- EPSS 0.38%
- Veröffentlicht 12.08.2026 16:56:43
- Zuletzt bearbeitet 17.08.2026 14:40:15
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to unsafe reflection.
CVE-2026-18246
- EPSS 0.19%
- Veröffentlicht 12.08.2026 16:55:44
- Zuletzt bearbeitet 17.08.2026 14:50:52
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to an interpretation conflict in the multipart parser.
CVE-2026-18106
- EPSS 0.37%
- Veröffentlicht 12.08.2026 16:53:28
- Zuletzt bearbeitet 17.08.2026 14:15:27
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of user-supplied path input.
CVE-2026-18144
- EPSS 0.24%
- Veröffentlicht 12.08.2026 16:52:27
- Zuletzt bearbeitet 17.08.2026 14:39:25
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.
CVE-2026-18098
- EPSS 0.19%
- Veröffentlicht 12.08.2026 16:50:04
- Zuletzt bearbeitet 17.08.2026 14:17:19
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and compromise system integrity due to an XML injection flaw.
CVE-2026-18683
- EPSS 0.81%
- Veröffentlicht 12.08.2026 16:49:07
- Zuletzt bearbeitet 17.08.2026 14:38:47
IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to privilege escalation via Navigator for i. An authenticated user could elevate privileges to a root user to execute commands.
CVE-2026-4942
- EPSS 0.25%
- Veröffentlicht 17.07.2026 19:32:02
- Zuletzt bearbeitet 12.08.2026 19:00:35
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to send a specifically crafted message and downgrade the Transport Layer Security (TLS) protocol to a version disabled in the server configuration.
CVE-2026-10852
- EPSS 0.29%
- Veröffentlicht 22.06.2026 19:32:28
- Zuletzt bearbeitet 09.07.2026 21:16:54
IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to denial of service in the WebSphere WebServer Plug-in component when an attacker can pass crafted requests to the web server.