VendorsIBMi7.2
Vulnerabilities

IBM I 7.2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

40CVEs
CVE-2023-30990
IBM i command execution
Published 2023-07-03 · Modified
9.8EPSS 0.010
CVE-2026-2311
IBM i is affected by a privilege escalation vulnerability in Web Administration GUI []
Published 2026-04-30 · Analyzed
9.8EPSS 0.002
CVE-2025-36004
IBM i privilege escalation
Published 2025-06-25 · Analyzed
8.8EPSS 0.005
CVE-2025-33103
IBM i privilege escalation
Published 2025-05-17 · Analyzed
8.8EPSS 0.004
CVE-2025-33109
IBM i privilege escalation
Published 2025-07-24 · Analyzed
8.8EPSS 0.004
CVE-2025-36367
IBM i is affected by a privilege escalation in IBM i SQL services
Published 2025-11-01 · Analyzed
8.8EPSS 0.003
CVE-2024-55898
IBM i privilege escalation
Published 2025-02-24 · Analyzed
8.5EPSS 0.004
CVE-2024-25050
IBM i privilege escalation
Published 2024-04-28 · Analyzed
8.4EPSS 0.003
CVE-2023-42006
IBM i information disclosure
Published 2023-12-01 · Modified
8.4EPSS 0.002
CVE-2024-22346
IBM i privilege escalation
Published 2024-03-14 · Modified
8.4EPSS 0.002
CVE-2023-38721
IBM i privilege escalation
Published 2023-08-14 · Modified
8.4EPSS 0.002
CVE-2023-30989
IBM i privilege escalation
Published 2023-07-16 · Modified
8.4EPSS 0.002
CVE-2023-30988
IBM i privilege escalation
Published 2023-07-16 · Modified
8.4EPSS 0.002
CVE-2021-20501
IBM i 7.1, 7.2, 7.3, and 7.4 SMTP allows a network attacker to send emails to non-existent local-domain recipients to the SMTP server, caused by using a non-default configuration. An attacker could exploit this vulnerability to consume unnecessary network bandwidth and disk space, and allow remote attackers to send spam email. IBM X-Force ID: 198056.
Published 2021-04-21 · Modified
8.2EPSS 0.013
CVE-2024-38330
IBM i privilege escalation
Published 2024-07-08 · Modified
7.8EPSS 0.003
CVE-2023-43064
IBM i code execution
Published 2023-12-25 · Modified
7.8EPSS 0.002
CVE-2024-27275
IBM i privilege escalation
Published 2024-06-15 · Modified
7.8EPSS 0.002
CVE-2023-40685
IBM i privilege escalation
Published 2023-10-29 · Modified
7.8EPSS 0.002
CVE-2023-40375
IBM i privilege escalation
Published 2023-09-28 · Modified
7.8EPSS 0.001
CVE-2023-40686
IBM i privilege escalation
Published 2023-10-29 · Modified
7.8EPSS 0.001
CVE-2023-40377
IBM i privilege escalation
Published 2023-10-16 · Modified
7.8EPSS 0.001
CVE-2023-40378
IBM i privilege escalation
Published 2023-10-15 · Modified
7.8EPSS 0.001
CVE-2024-27264
IBM Performance Tools for i privilege escalation
Published 2024-05-22 · Analyzed
7.8EPSS 0.001
CVE-2017-1460
IBM i OSPF 6.1, 7.1, 7.2, and 7.3 is vulnerable when a rogue router spoofs its origin. Routing tables are affected by a missing LSA, which may lead to loss of connectivity. IBM X-Force ID: 128379.
Published 2017-07-31 · Modified
7.5EPSS 0.014
CVE-2024-31879
IBM i denial of service
Published 2024-05-18 · Analyzed
7.5EPSS 0.009
CVE-2025-33122
IBM i privilege escalation
Published 2025-06-17 · Analyzed
7.5EPSS 0.004
CVE-2023-23470
IBM i privilege escalation
Published 2023-05-04 · Modified
7.2EPSS 0.005
CVE-2021-39056
The IBM i 7.1, 7.2, 7.3, and 7.4 Extended Dynamic Remote SQL server (EDRSQL) could allow a remote authenticated user to send a specially crafted request and cause a denial of service. IBM X-Force ID: 214537.
Published 2022-01-13 · Modified
6.5EPSS 0.013
CVE-2025-36371
IBM i Information Disclosure
Published 2025-11-19 · Analyzed
6.5EPSS 0.003
CVE-2019-4040
IBM I 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 156164.
Published 2019-01-31 · Modified
6.1EPSS 0.013
CVE-2019-4450
IBM i 7.2, 7.3, and 7.4 for i is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 163492.
Published 2019-11-09 · Modified
6.1EPSS 0.007
CVE-2021-38876
IBM i 7.2, 7.3, and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 208404.
Published 2021-12-30 · Modified
6.1EPSS 0.006
CVE-2019-4381
IBM i 7.27.3 Clustering could allow a local attacker to obtain sensitive information, caused by the use of advanced node failure detection using the REST API to interface with the HMC. An attacker could exploit this vulnerability to obtain HMC credentials. IBM X-Force ID: 162159.
Published 2019-06-14 · Modified
5.9EPSS 0.004
CVE-2022-34358
IBM i 7.2, 7.3, 7.4, and 7.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 230516.
Published 2022-07-13 · Modified
5.4EPSS 0.005
CVE-2025-3218
IBM i improper certificate validation
Published 2025-05-07 · Analyzed
5.4EPSS 0.003
CVE-2022-22481
IBM Navigator for i 7.2, 7.3, and 7.4 (heritage version) could allow a remote attacker to obtain access to the web interface without valid credentials. By modifying the sign on request, an attacker can gain visibility to the fully qualified domain name of the target system and the navigator tasks page, however they do not gain the ability to perform those tasks on the system or see any specific system data. IBM X-Force ID: 225899.
Published 2022-05-09 · Modified
5.3EPSS 0.012
CVE-2024-31878
IBM i information disclosure
Published 2024-06-07 · Modified
5.3EPSS 0.004
CVE-2020-4345
IBM i 7.2, 7.3, and 7.4 users running complex SQL statements under a specific set of circumstances may allow a local user to obtain sensitive information that they should not have access to. IBM X-Force ID: 178318.
Published 2020-05-17 · Modified
3.3EPSS 0.003
CVE-2024-31870
IBM i information disclosure
Published 2024-06-15 · Modified
3.3EPSS 0.002
CVE-2024-35122
IBM i denial of service
Published 2025-01-24 · Modified
2.8EPSS 0.002