VendorsIBMiall versions
Vulnerabilities

IBM I

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

261CVEs
CVE-2026-6936
IBM i is Affected by a Denial of Service Vulnerability []
Published 2026-05-27 · Analyzed
6.5EPSS 0.004
CVE-2026-17419
IBM i is Affected By Multiple Vulnerabilities in SQL
Published 2026-08-12 · Analyzed
6.5EPSS 0.004
CVE-2026-16878
IBM i is Affected By Multiple Vulnerabilities in NetServer
Published 2026-08-13 · Analyzed
6.5EPSS 0.004
CVE-2024-52895
IBM i denial of service
Published 2025-02-14 · Analyzed
6.5EPSS 0.004
CVE-2024-49823
IBM Common Cryptographic Architecture denial of service
Published 2025-03-11 · Analyzed
6.5EPSS 0.004
CVE-2026-18671
IBM i is Affected By Multiple Vulnerabilities in NetServer
Published 2026-08-13 · Undergoing Analysis
6.5EPSS 0.004
CVE-2026-17259
IBM i is Affected By Multiple Vulnerabilities in Debug Server
Published 2026-09-04 · Analyzed
6.5EPSS 0.004
CVE-2026-17273
IBM i is Affected By Multiple Vulnerabilities in Debug Server
Published 2026-09-04 · Analyzed
6.5EPSS 0.004
CVE-2026-18076
IBM i is Affected By Multiple Vulnerabilities in Debug Server
Published 2026-09-04 · Analyzed
6.5EPSS 0.003
CVE-2026-18078
IBM i is Affected By Denial of Service Vulnerability in Save Restore []
Published 2026-09-04 · Analyzed
6.5EPSS 0.003
CVE-2026-18887
IBM i is Affected By Sensitive Information Exposure Vulnerability in PASE []
Published 2026-09-04 · Analyzed
6.5EPSS 0.003
CVE-2025-36371
IBM i Information Disclosure
Published 2025-11-19 · Analyzed
6.5EPSS 0.003
CVE-2022-22423
IBM Common Cryptographic Architecture (CCA 5.x MTM for 4767 and CCA 7.x MTM for 4769) could allow a local user to cause a denial of service due to improper input validation. IBM X-Force ID: 223596.
Published 2022-09-23 · Modified
6.5EPSS 0.003
CVE-2026-16694
IBM i is Affected By Stored Cross-site Scripting for i
Published 2026-08-12 · Analyzed
6.4EPSS 0.002
CVE-2022-43859
IBM Navigator for i SQL injection
Published 2022-12-22 · Modified
6.3EPSS 0.006
CVE-2026-17420
IBM i is Affected By Multiple Vulnerabilities in SQL
Published 2026-08-12 · Analyzed
6.3EPSS 0.004
CVE-2026-18250
IBM i is Affected By Multiple Vulnerabilities in Navigator for i
Published 2026-08-12 · Analyzed
6.3EPSS 0.003
CVE-2023-28514
IBM MQ information disclosure
Published 2023-05-19 · Modified
6.2EPSS 0.002
CVE-2021-38949
IBM MQ 7.5, 8.0, 9.0 LTS, 9.1 CD, and 9.1 LTS stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 211403.
Published 2021-11-16 · Modified
6.2EPSS 0.002
CVE-2019-4040
IBM I 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 156164.
Published 2019-01-31 · Modified
6.1EPSS 0.013
CVE-2020-4657
IBM Sterling B2B Integrator 5.2.0.0 through 6.0.3.2 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186094.
Published 2020-12-16 · Modified
6.1EPSS 0.007
CVE-2020-4658
IBM Sterling File Gateway 2.2.0.0 through 6.0.3.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186095.
Published 2020-12-16 · Modified
6.1EPSS 0.007
CVE-2019-4450
IBM i 7.2, 7.3, and 7.4 for i is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 163492.
Published 2019-11-09 · Modified
6.1EPSS 0.007
CVE-2021-38876
IBM i 7.2, 7.3, and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 208404.
Published 2021-12-30 · Modified
6.1EPSS 0.006
CVE-2022-22477
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 225605.
Published 2022-07-14 · Modified
6.1EPSS 0.006
CVE-2022-38712
"IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Web services could allow a man-in-the-middle attacker to conduct SOAPAction spoofing to execute unwanted or unauthorized operations. IBM X-Force ID: 234762."
Published 2022-11-03 · Modified
5.9EPSS 0.005
CVE-2019-4381
IBM i 7.27.3 Clustering could allow a local attacker to obtain sensitive information, caused by the use of advanced node failure detection using the REST API to interface with the HMC. An attacker could exploit this vulnerability to obtain HMC credentials. IBM X-Force ID: 162159.
Published 2019-06-14 · Modified
5.9EPSS 0.004
CVE-2026-10571
IBM WebSphere Application Server Liberty is affected by a denial of service
Published 2026-08-13 · Analyzed
5.7EPSS 0.006
CVE-2024-45072
IBM WebSphere Application Server XML external entity injection
Published 2024-10-16 · Analyzed
5.5EPSS 0.004
CVE-2024-45071
IBM WebSphere Application Server cross-site scripting
Published 2024-10-16 · Analyzed
5.5EPSS 0.002
CVE-2026-17270
IBM i is Affected By Multiple Vulnerabilities in Debug Server
Published 2026-09-04 · Analyzed
5.5EPSS 0.002
CVE-2026-17469
IBM i is Affected By Denial of Service Vulnerabilities in Line Printer Daemon [, ]
Published 2026-09-04 · Analyzed
5.5EPSS 0.002
CVE-2023-28950
IBM MQ information disclosure
Published 2023-05-19 · Modified
5.5EPSS 0.002
CVE-2026-18858
IBM i is Affected By Obtaining Sensitive Information Vulnerability in OpenSSH []
Published 2026-09-04 · Analyzed
5.5EPSS 0.001
CVE-2021-20562
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_3 and 6.1.0.0 through 6.1.0.2 vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199232.
Published 2021-07-27 · Modified
5.4EPSS 0.009
CVE-2024-51463
IBM i server-side request forgery
Published 2024-12-21 · Modified
5.41 PoCEPSS 0.009
CVE-2020-4578
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 184433.
Published 2020-09-10 · Modified
5.4EPSS 0.007
CVE-2022-34165
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.9 are vulnerable to HTTP header injection, caused by improper validation. This could allow an attacker to conduct various attacks against the vulnerable system, including cache poisoning and cross-site scripting. IBM X-Force ID: 229429.
Published 2022-09-09 · Modified
5.4EPSS 0.006
CVE-2022-34336
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 229714.
Published 2022-09-13 · Modified
5.4EPSS 0.005
CVE-2022-34358
IBM i 7.2, 7.3, 7.4, and 7.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 230516.
Published 2022-07-13 · Modified
5.4EPSS 0.005
← Prev5 / 7Next →