VendorsIBMiany version
Vulnerabilities

IBM I any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

115CVEs
CVE-2020-4658
IBM Sterling File Gateway 2.2.0.0 through 6.0.3.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186095.
Published 2020-12-16 · Modified
6.1EPSS 0.007
CVE-2022-22477
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 225605.
Published 2022-07-14 · Modified
6.1EPSS 0.006
CVE-2022-38712
"IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Web services could allow a man-in-the-middle attacker to conduct SOAPAction spoofing to execute unwanted or unauthorized operations. IBM X-Force ID: 234762."
Published 2022-11-03 · Modified
5.9EPSS 0.005
CVE-2026-10571
IBM WebSphere Application Server Liberty is affected by a denial of service
Published 2026-08-13 · Analyzed
5.7EPSS 0.006
CVE-2024-45072
IBM WebSphere Application Server XML external entity injection
Published 2024-10-16 · Analyzed
5.5EPSS 0.004
CVE-2024-45071
IBM WebSphere Application Server cross-site scripting
Published 2024-10-16 · Analyzed
5.5EPSS 0.002
CVE-2023-28950
IBM MQ information disclosure
Published 2023-05-19 · Modified
5.5EPSS 0.002
CVE-2021-20562
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_3 and 6.1.0.0 through 6.1.0.2 vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199232.
Published 2021-07-27 · Modified
5.4EPSS 0.009
CVE-2024-51463
IBM i server-side request forgery
Published 2024-12-21 · Modified
5.41 PoCEPSS 0.009
CVE-2020-4578
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 184433.
Published 2020-09-10 · Modified
5.4EPSS 0.007
CVE-2022-34165
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.9 are vulnerable to HTTP header injection, caused by improper validation. This could allow an attacker to conduct various attacks against the vulnerable system, including cache poisoning and cross-site scripting. IBM X-Force ID: 229429.
Published 2022-09-09 · Modified
5.4EPSS 0.006
CVE-2022-34336
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 229714.
Published 2022-09-13 · Modified
5.4EPSS 0.005
CVE-2022-34358
IBM i 7.2, 7.3, 7.4, and 7.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 230516.
Published 2022-07-13 · Modified
5.4EPSS 0.005
CVE-2022-40750
IBM WebSphere Application Server cross-site scripting
Published 2022-11-11 · Modified
5.4EPSS 0.004
CVE-2023-26283
IBM WebSphere Application Server cross-site scripting
Published 2023-03-22 · Modified
5.4EPSS 0.004
CVE-2025-2950
IBM i improper HTTP header neutralization
Published 2025-04-18 · Analyzed
5.4EPSS 0.003
CVE-2026-1561
IBM WebSphere Application Server Liberty Server-Side Request Forgery
Published 2026-03-25 · Analyzed
5.4EPSS 0.003
CVE-2025-3218
IBM i improper certificate validation
Published 2025-05-07 · Analyzed
5.4EPSS 0.003
CVE-2026-11383
Cross-site Scripting in IBM WebSphere Application Server shipped with Tivoli System Automation Application Manager
Published 2026-07-30 · Analyzed
5.4EPSS 0.002
CVE-2020-4365
IBM WebSphere Application Server 8.5 is vulnerable to server-side request forgery. By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to obtain sensitive data. IBM X-Force ID: 178964.
Published 2020-05-14 · Modified
5.3EPSS 0.014
CVE-2020-4761
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_2, 6.0.0.0 through 6.0.3.2, and 6.1.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 188895.
Published 2021-01-05 · Modified
5.3EPSS 0.013
CVE-2022-22473
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information caused by improper handling of Administrative Console data. This information could be used in further attacks against the system. IBM X-Force ID: 225347.
Published 2022-07-14 · Modified
5.3EPSS 0.011
CVE-2023-45177
IBM MQ denial of service
Published 2024-03-20 · Analyzed
5.3EPSS 0.006
CVE-2024-51464
IBM i authentication bypass
Published 2024-12-21 · Modified
4.31 PoCEPSS 0.014
CVE-2019-4377
IBM Sterling B2B Integrator 6.0.0.0 and 6.0.0.1 reveals sensitive information from a stack trace that could be used in further attacks against the system. IBM X-Force ID: 162803.
Published 2019-06-25 · Modified
4.3EPSS 0.013
CVE-2020-4299
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.1 could expose sensitive information to a user through a specially crafted HTTP request. IBM X-Force ID: 176606.
Published 2020-05-14 · Modified
4.3EPSS 0.010
CVE-2026-17109
IBM i is Affected By Multiple Vulnerabilities in SQL
Published 2026-08-12 · Analyzed
4.3EPSS 0.004
CVE-2026-17222
IBM i is Affected By Multiple Vulnerabilities in SQL
Published 2026-08-12 · Analyzed
4.3EPSS 0.003
CVE-2025-27907
IBM WebSphere Application Server server-side request forgery
Published 2025-04-22 · Analyzed
4.1EPSS 0.003
CVE-2022-42436
IBM MQ information disclosure
Published 2023-02-08 · Modified
4.0EPSS 0.002
CVE-2026-17043
IBM i is Affected By Multiple Vulnerabilities in Digital Certificate Manager
Published 2026-08-13 · Analyzed
3.8EPSS 0.005
CVE-2023-33855
IBM Common Cryptographic Architecture information disclosure
Published 2024-03-26 · Analyzed
3.7EPSS 0.005
CVE-2024-41760
IBM Common Cryptographic Architecture information disclosure
Published 2025-03-11 · Analyzed
3.7EPSS 0.003
CVE-2020-4629
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local user with specialized access to obtain sensitive information from a detailed technical error message. This information could be used in further attacks against the system. IBM X-Force ID: 185370.
Published 2020-09-30 · Modified
3.3EPSS 0.003
CVE-2024-35122
IBM i denial of service
Published 2025-01-24 · Modified
2.8EPSS 0.002
← Prev3 / 3