VendorsIBMiany version
Vulnerabilities

IBM I any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

115CVEs
CVE-2020-9412
TIBCO Managed File Transfer Platform Server for IBM i Arbitrary Command Execution
Published 2020-06-09 · Modified
10.0EPSS 0.023
CVE-2020-9411
TIBCO Managed File Transfer Platform Server for IBM i Authentication Bypass
Published 2020-06-09 · Modified
10.0EPSS 0.014
CVE-2026-16860
IBM i is Affected By Remote Code Execution Vulnerability []
Published 2026-08-12 · Analyzed
9.9EPSS 0.005
CVE-2026-17276
IBM i is Affected By Multiple Vulnerabilities in Navigator for i
Published 2026-08-12 · Analyzed
9.9EPSS 0.003
CVE-2025-36038
IBM WebSphere Application Server code execution
Published 2025-06-25 · Analyzed
9.8EPSS 0.108
CVE-2023-23477
IBM WebSphere Application Server code execution
Published 2023-02-03 · Modified
9.8EPSS 0.019
CVE-2026-9072
WebSphere Application Server Remote Code Execution
Published 2026-06-22 · Modified
9.8EPSS 0.007
CVE-2026-17218
IBM i is Affected By Remote Code Execution Vulnerability in Line Printer Daemon []
Published 2026-08-12 · Analyzed
9.8EPSS 0.006
CVE-2025-2947
IBM i privilege escalation
Published 2025-04-17 · Analyzed
9.8EPSS 0.004
CVE-2025-14917
IBM WebSphere Application Server Liberty could provide weaker than expected security
Published 2026-03-25 · Analyzed
9.8EPSS 0.004
CVE-2026-17206
IBM i is Affected By Multiple Vulnerabilities in Host Servers
Published 2026-08-13 · Analyzed
9.8EPSS 0.004
CVE-2026-14525
IBM WebSphere Application Server Liberty is affected by an authenication bypass
Published 2026-08-13 · Analyzed
9.4EPSS 0.003
CVE-2026-11707
Multiple vulnerabilities have been identified in IBM WebSphere Application Server shipped with Tivoli System Automation Application Manager
Published 2026-07-30 · Analyzed
9.3EPSS 0.002
CVE-2026-8646
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities
Published 2026-06-22 · Analyzed
9.1EPSS 0.006
CVE-2026-9006
IBM WebSphere Application Server is affected by server-side request forgery
Published 2026-06-22 · Analyzed
9.1EPSS 0.004
CVE-2019-4728
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_2, 6.0.0.0 through 6.0.3.2, and 6.1.0.0 could allow a remote attacker to execute arbitrary code on the system, caused by the deserialization of untrusted data. By sending specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code with SYSTEM privileges. IBM X-Force ID: 172452.
Published 2021-01-05 · Modified
9.0EPSS 0.050
CVE-2022-22495
IBM i 7.3, 7.4, and 7.5 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 226941.
Published 2022-05-24 · Modified
8.8EPSS 0.022
CVE-2020-4762
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_2, 6.0.0.0 through 6.0.3.2, and 6.1.0.0 could allow an authenticated user to create a privileged account due to improper access controls. IBM X-Force ID: 188896.
Published 2021-01-05 · Modified
8.8EPSS 0.013
CVE-2021-29736
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote user to gain elevated privileges on the system. IBM X-Force ID: 201300.
Published 2021-07-30 · Modified
8.8EPSS 0.011
CVE-2021-29754
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a privilege escalation vulnerability when using the SAML Web Inbound Trust Association Interceptor (TAI). IBM X-Force ID: 202006.
Published 2021-06-11 · Modified
8.8EPSS 0.007
CVE-2025-36004
IBM i privilege escalation
Published 2025-06-25 · Analyzed
8.8EPSS 0.005
CVE-2026-18669
IBM i is Affected By A Privilege Escalation Vulnerability []
Published 2026-08-12 · Analyzed
8.8EPSS 0.005
CVE-2026-18713
IBM i is Affected By Multiple Vulnerabilities in Navigator for i
Published 2026-08-12 · Analyzed
8.8EPSS 0.005
CVE-2026-17110
IBM i is Affected By Multiple Vulnerabilities in SQL
Published 2026-08-12 · Analyzed
8.8EPSS 0.005
CVE-2026-17223
IBM i is Affected By Multiple Vulnerabilities in Host Servers
Published 2026-08-13 · Analyzed
8.8EPSS 0.004
CVE-2026-8858
WebSphere Application Server Remote Code Execution
Published 2026-06-22 · Modified
8.8EPSS 0.004
CVE-2026-17029
IBM i is Affected By Multiple Vulnerabilities in Java Secure Sockets Extension
Published 2026-08-13 · Analyzed
8.8EPSS 0.001
CVE-2024-55898
IBM i privilege escalation
Published 2025-02-24 · Analyzed
8.5EPSS 0.004
CVE-2026-17418
IBM i is Affected By Multiple Vulnerabilities in SQL
Published 2026-08-12 · Analyzed
8.5EPSS 0.002
CVE-2026-18235
IBM i is Affected By Multiple Vulnerabilities in Navigator for i
Published 2026-08-12 · Analyzed
8.3EPSS 0.003
CVE-2020-4949
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 192025.
Published 2021-01-26 · Modified
8.2EPSS 0.048
CVE-2026-16904
IBM i is Affected By improper privilege management in Navigator for i
Published 2026-08-12 · Analyzed
8.1EPSS 0.005
CVE-2026-17045
IBM i is Affected By Multiple Vulnerabilities in Digital Certificate Manager
Published 2026-08-13 · Analyzed
8.1EPSS 0.003
CVE-2026-17069
IBM i is Affected By Multiple Vulnerabilities in Digital Certificate Manager
Published 2026-08-13 · Analyzed
8.1EPSS 0.002
CVE-2021-20354
IBM WebSphere Application Server 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 194883.
Published 2021-02-18 · Modified
7.8EPSS 0.041
CVE-2024-31890
IBM i privilege escalation
Published 2024-06-21 · Analyzed
7.8EPSS 0.002
CVE-2026-16863
IBM i is Affected By Out-of-Bounds Read Vulnerability []
Published 2026-08-12 · Analyzed
7.7EPSS 0.003
CVE-2026-16907
IBM i is Affected By Multiple Vulnerabilities in the Debug Server
Published 2026-08-12 · Analyzed
7.6EPSS 0.004
CVE-2025-33104
IBM WebSphere Application Server cross
Published 2025-05-14 · Analyzed
7.6EPSS 0.002
CVE-2020-4870
IBM MQ 9.2 CD and LTS are vulnerable to a denial of service attack caused by an error processing connecting applications. IBM X-Force ID: 190833.
Published 2020-12-21 · Modified
7.5EPSS 0.017
1 / 3Next →