VendorsIBMiall versions
Vulnerabilities

IBM I

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

261CVEs
CVE-2026-17110
IBM i is Affected By Multiple Vulnerabilities in SQL
Published 2026-08-12 · Analyzed
8.8EPSS 0.007
CVE-2026-16674
IBM i is Affected By Multiple Vulnerabilities in WebSphere Application Server Liberty
Published 2026-08-13 · Analyzed
8.8EPSS 0.007
CVE-2026-18669
IBM i is Affected By A Privilege Escalation Vulnerability []
Published 2026-08-12 · Analyzed
8.8EPSS 0.007
CVE-2021-29754
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a privilege escalation vulnerability when using the SAML Web Inbound Trust Association Interceptor (TAI). IBM X-Force ID: 202006.
Published 2021-06-11 · Modified
8.8EPSS 0.007
CVE-2026-18683
IBM i is Affected By privilege escalation in Navigator for i
Published 2026-08-12 · Analyzed
8.8EPSS 0.007
CVE-2025-33108
IBM Backup Recovery and Media Services for i code execution
Published 2025-06-14 · Analyzed
8.8EPSS 0.006
CVE-2026-16908
IBM i is Affected By Multiple SQL Vulnerabilities [, ]
Published 2026-08-13 · Undergoing Analysis
8.8EPSS 0.006
CVE-2025-36004
IBM i privilege escalation
Published 2025-06-25 · Analyzed
8.8EPSS 0.005
CVE-2026-18713
IBM i is Affected By Multiple Vulnerabilities in Navigator for i
Published 2026-08-12 · Analyzed
8.8EPSS 0.005
CVE-2026-16856
IBM i is Affected By Multiple Vulnerabilities in Domain Name System
Published 2026-08-12 · Analyzed
8.8EPSS 0.005
CVE-2026-16722
IBM i is Affected By An Unauthorized Privileges Vulnerability in SQL []
Published 2026-08-13 · Undergoing Analysis
8.8EPSS 0.005
CVE-2026-17082
IBM i is Affected By Multiple Vulnerabilities in the Debug Server
Published 2026-08-12 · Analyzed
8.8EPSS 0.005
CVE-2026-7870
IBM i is Affected by Privilege Escalation []
Published 2026-06-11 · Analyzed
8.8EPSS 0.005
CVE-2025-33103
IBM i privilege escalation
Published 2025-05-17 · Analyzed
8.8EPSS 0.004
CVE-2026-8858
WebSphere Application Server Remote Code Execution
Published 2026-06-22 · Modified
8.8EPSS 0.004
CVE-2025-33109
IBM i privilege escalation
Published 2025-07-24 · Analyzed
8.8EPSS 0.004
CVE-2025-36367
IBM i is affected by a privilege escalation in IBM i SQL services
Published 2025-11-01 · Analyzed
8.8EPSS 0.003
CVE-2026-18341
IBM i is Affected By Buffer Overflow Vulnerability []
Published 2026-09-04 · Analyzed
8.8EPSS 0.002
CVE-2025-36119
IBM i authentication bypass
Published 2025-08-08 · Analyzed
8.8EPSS 0.002
CVE-2026-17029
IBM i is Affected By Multiple Vulnerabilities in Java Secure Sockets Extension
Published 2026-08-13 · Analyzed
8.8EPSS 0.002
CVE-2026-16987
IBM i is Affected By An Improper Validation Vulnerability in PASE []
Published 2026-08-13 · Undergoing Analysis
8.8EPSS 0.002
CVE-2026-18101
IBM i is Affected By Multiple Vulnerabilities in WebSphere Application Server Liberty
Published 2026-08-13 · Analyzed
8.8EPSS 0.001
CVE-2026-17502
IBM i is Affected By Multiple Vulnerabilities in NetServer
Published 2026-08-13 · Analyzed
8.6EPSS 0.004
CVE-2013-5385
The OSPF implementation in IBM i 6.1 and 7.1, in z/OS on zSeries servers, and in Networking Operating System (aka NOS, formerly BLADE Operating System) does not properly validate Link State Advertisement (LSA) type 1 packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.
Published 2014-01-02 · Modified
8.5EPSS 0.035
CVE-2024-55898
IBM i privilege escalation
Published 2025-02-24 · Analyzed
8.5EPSS 0.004
CVE-2026-16967
IBM i is Affected By Multiple SQL Vulnerabilities [, ]
Published 2026-08-13 · Undergoing Analysis
8.5EPSS 0.003
CVE-2026-17418
IBM i is Affected By Multiple Vulnerabilities in SQL
Published 2026-08-12 · Analyzed
8.5EPSS 0.003
CVE-2024-25050
IBM i privilege escalation
Published 2024-04-28 · Analyzed
8.4EPSS 0.003
CVE-2023-42006
IBM i information disclosure
Published 2023-12-01 · Modified
8.4EPSS 0.002
CVE-2024-22346
IBM i privilege escalation
Published 2024-03-14 · Modified
8.4EPSS 0.002
CVE-2023-38721
IBM i privilege escalation
Published 2023-08-14 · Modified
8.4EPSS 0.002
CVE-2023-30989
IBM i privilege escalation
Published 2023-07-16 · Modified
8.4EPSS 0.002
CVE-2023-30988
IBM i privilege escalation
Published 2023-07-16 · Modified
8.4EPSS 0.002
CVE-2026-18235
IBM i is Affected By Multiple Vulnerabilities in Navigator for i
Published 2026-08-12 · Analyzed
8.3EPSS 0.005
CVE-2026-17095
IBM i is Affected By Multiple Vulnerabilities in Navigator for i
Published 2026-08-12 · Analyzed
8.3EPSS 0.005
CVE-2020-4949
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 192025.
Published 2021-01-26 · Modified
8.2EPSS 0.048
CVE-2021-20501
IBM i 7.1, 7.2, 7.3, and 7.4 SMTP allows a network attacker to send emails to non-existent local-domain recipients to the SMTP server, caused by using a non-default configuration. An attacker could exploit this vulnerability to consume unnecessary network bandwidth and disk space, and allow remote attackers to send spam email. IBM X-Force ID: 198056.
Published 2021-04-21 · Modified
8.2EPSS 0.013
CVE-2026-17220
IBM i is Affected By Multiple Vulnerabilities in Host Servers
Published 2026-08-13 · Undergoing Analysis
8.2EPSS 0.006
CVE-2026-17485
IBM i is Affected By Denial of Service Vulnerability []
Published 2026-08-12 · Analyzed
8.2EPSS 0.005
CVE-2026-17272
IBM i is Affected By a Denial of Service in HTTP Server []
Published 2026-08-13 · Analyzed
8.2EPSS 0.005
← Prev2 / 7Next →