<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – IBM iSeries (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/ibm-i.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/ibm-i-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – IBM iSeries (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:35 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-7770 – IBM i Access Family 1.1.5.0 through 1.1.9.12 IBM i Access Client Solutions (ACS)...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7770</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7770</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7770</strong></p>
  <p>IBM i Access Family 1.1.5.0 through 1.1.9.12 IBM i Access Client Solutions (ACS) is vulnerable to remote code execution when configured to listen for requests from IBM i Navigator.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7770">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1376 – IBM i 7.6 could allow a remote attacker to cause a denial of service using faile...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1376</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1376</guid>
    <pubDate>Tue, 17 Mar 2026 22:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1376</strong></p>
  <p>IBM i 7.6 could allow a remote attacker to cause a denial of service using failed authentication connections due to improper allocation of resources.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1376">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-36367 – IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 is vulnerable to privilege escalation caused b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36367</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36367</guid>
    <pubDate>Sat, 01 Nov 2025 12:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-36367</strong></p>
  <p>IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 is vulnerable to privilege escalation caused by an invalid IBM i SQL services authorization check. A malicious actor can use the elevated privileges of another user profile to gain root access to the host operating system.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36367">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-42958 – Due to a missing authentication check in the SAP NetWeaver application on IBM i-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-42958</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-42958</guid>
    <pubDate>Tue, 09 Sep 2025 02:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-42958</strong></p>
  <p>Due to a missing authentication check in the SAP NetWeaver application on IBM i-series, the application allows high privileged unauthorized users to read, modify, or delete sensitive information, as well as access administrative or privileged functionalities. This results in a high impact on the confidentiality, integrity, and availability of the application.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-42958">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-36119 – IBM i 7.3, 7.4, 7.5, and 7.6 is affected by an authenticated user obtaining elev...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36119</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36119</guid>
    <pubDate>Fri, 08 Aug 2025 15:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-36119</strong></p>
  <p>IBM i 7.3, 7.4, 7.5, and 7.6 is affected by an authenticated user obtaining elevated privileges with IBM Digital Certificate Manager for i (DCM) due to a web session hijacking vulnerability. An authenticated user without administrator privileges could exploit this vulnerability to perform actions in DCM as an administrator.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36119">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-33109 – IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to a privilege escalation caused...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-33109</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-33109</guid>
    <pubDate>Thu, 24 Jul 2025 15:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-33109</strong></p>
  <p>IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to a privilege escalation caused by an invalid database authority check.  A bad actor could execute a database procedure or function without having all required permissions, in addition to causing denial of service for some database actions.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-33109">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-36004 – IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user to gain elevated privileges due ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36004</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36004</guid>
    <pubDate>Wed, 25 Jun 2025 03:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-36004</strong></p>
  <p>IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user to gain elevated privileges due to an unqualified library call in IBM Facsimile Support for i. A malicious actor could cause user-controlled code to run with administrator privilege.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36004">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-33122 – IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 could allow a user to gain elevated privileges...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-33122</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-33122</guid>
    <pubDate>Tue, 17 Jun 2025 18:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-33122</strong></p>
  <p>IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 could allow a user to gain elevated privileges due to an unqualified library call in IBM Advanced Job Scheduler for i. A malicious actor could cause user-controlled code to run with administrator privilege.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-33122">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-33103 – IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 product IBM TCP/IP Connectivity Utilities for ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-33103</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-33103</guid>
    <pubDate>Sat, 17 May 2025 16:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-33103</strong></p>
  <p>IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 product IBM TCP/IP Connectivity Utilities for i contains a privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain root access to the host operating system.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-33103">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-2947 – IBM i 7.6 

contains a privilege escalation vulnerability due to incorrect profi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2947</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2947</guid>
    <pubDate>Thu, 17 Apr 2025 17:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-2947</strong></p>
  <p>IBM i 7.6   contains a privilege escalation vulnerability due to incorrect profile swapping in an OS command.  A malicious actor can use the command to elevate privileges to gain root access to the host operating system.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-278</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2947">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-55898 – IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user with the capability to compile o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-55898</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-55898</guid>
    <pubDate>Mon, 24 Feb 2025 02:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-55898</strong></p>
  <p>IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user with the capability to compile or restore a program to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privilege.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-55898">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-31890 – IBM i 7.3, 7.4, and 7.5 product IBM TCP/IP Connectivity Utilities for i contains...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-31890</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-31890</guid>
    <pubDate>Fri, 21 Jun 2024 10:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-31890</strong></p>
  <p>IBM i 7.3, 7.4, and 7.5 product IBM TCP/IP Connectivity Utilities for i contains a local privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain root access to the host operating system.  IBM X-Force ID:  288171.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-31890">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-27275 – IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-27275</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-27275</guid>
    <pubDate>Sat, 15 Jun 2024 14:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-27275</strong></p>
  <p>IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability caused by an insufficient authority requirement. A local user without administrator privilege can configure a physical file trigger to execute with the privileges of a user socially engineered to access the target file. The correction is to require administrator privilege to configure trigger support.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27275">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-31879 – IBM i 7.2, 7.3, and 7.4 could allow a remote attacker to execute arbitrary code ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-31879</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-31879</guid>
    <pubDate>Sat, 18 May 2024 16:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-31879</strong></p>
  <p>IBM i 7.2, 7.3, and 7.4 could allow a remote attacker to execute arbitrary code leading to a denial of service of network ports on the system, caused by the deserialization of untrusted data.  IBM X-Force ID:  287539.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-31879">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-25050 – IBM i 7.2, 7.3, 7.4, 7.5 and IBM Rational Development Studio for i 7.2, 7.3, 7.4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-25050</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-25050</guid>
    <pubDate>Sun, 28 Apr 2024 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-25050</strong></p>
  <p>IBM i 7.2, 7.3, 7.4, 7.5 and IBM Rational Development Studio for i 7.2, 7.3, 7.4, 7.5 networking and compiler infrastructure could allow a local user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privileges.  IBM X-Force ID:  283242.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-25050">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22346 – Db2 for IBM i 7.2, 7.3, 7.4, and 7.5 infrastructure could allow a local user to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22346</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22346</guid>
    <pubDate>Thu, 14 Mar 2024 19:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22346</strong></p>
  <p>Db2 for IBM i 7.2, 7.3, 7.4, and 7.5 infrastructure could allow a local user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privilege.  IBM X-Force ID:  280203.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22346">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-43064 – Facsimile Support for IBM i 7.2, 7.3, 7.4, and 7.5 could allow a local user to g...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-43064</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-43064</guid>
    <pubDate>Mon, 25 Dec 2023 03:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-43064</strong></p>
  <p>Facsimile Support for IBM i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqualified library call.  A malicious actor could cause arbitrary code to run with the privilege of the user invoking the facsimile support.  IBM X-Force ID:  267689.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-43064">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-45185 – IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-45185</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-45185</guid>
    <pubDate>Thu, 14 Dec 2023 14:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-45185</strong></p>
  <p>IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an attacker to execute remote code.  Due to improper authority checks the attacker could perform operations on the PC under the user's authority.  IBM X-Force ID:  268273.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45185">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-45182 – IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-45182</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-45182</guid>
    <pubDate>Thu, 14 Dec 2023 14:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-45182</strong></p>
  <p>IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 is vulnerable to having its key for an encrypted password decoded. By somehow gaining access to the encrypted password, a local attacker could exploit this vulnerability to obtain the password to other systems. IBM X-Force ID: 268265.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-922</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45182">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-40685 – Management Central as part of IBM i 7.2, 7.3, 7.4, and 7.5 Navigator contains a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40685</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40685</guid>
    <pubDate>Sun, 29 Oct 2023 02:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-40685</strong></p>
  <p>Management Central as part of IBM i 7.2, 7.3, 7.4, and 7.5 Navigator contains a local privilege escalation vulnerability.  A malicious actor with command line access to the operating system can exploit this vulnerability to elevate privileges to gain root access to the operating system.  IBM X-Force ID:  264116.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40685">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-40375 – Integrated application server for IBM i 7.2, 7.3, 7.4, and 7.5 contains a local ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40375</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40375</guid>
    <pubDate>Thu, 28 Sep 2023 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-40375</strong></p>
  <p>Integrated application server for IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability.  A malicious actor with command line access to the host operating system can elevate privileges to gain root access to the host operating system.  IBM X-Force ID:  263580.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40375">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-38721 – The IBM i 7.2, 7.3, 7.4, and 7.5 product Facsimile Support for i contains a loca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38721</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38721</guid>
    <pubDate>Mon, 14 Aug 2023 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-38721</strong></p>
  <p>The IBM i 7.2, 7.3, 7.4, and 7.5 product Facsimile Support for i contains a local privilege escalation vulnerability.   A malicious actor could gain access to a command line with elevated privileges allowing root access to the host operating system.  IBM X-Force ID:  262173.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38721">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-30988 – The IBM i 7.2, 7.3, 7.4, and 7.5 product Facsimile Support for i contains a loca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-30988</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-30988</guid>
    <pubDate>Sun, 16 Jul 2023 23:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-30988</strong></p>
  <p>The IBM i 7.2, 7.3, 7.4, and 7.5 product Facsimile Support for i contains a local privilege escalation vulnerability.  A malicious actor with command line access to the host operating system can elevate privileges to gain root access to the host operating system.  IBM X-Force ID:  254016.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-30988">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-30990 – IBM i 7.2, 7.3, 7.4, and 7.5 could allow a remote attacker to execute CL command...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-30990</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-30990</guid>
    <pubDate>Tue, 04 Jul 2023 00:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-30990</strong></p>
  <p>IBM i 7.2, 7.3, 7.4, and 7.5 could allow a remote attacker to execute CL commands as QUSER, caused by an exploitation of DDM architecture.  IBM X-Force ID:  254036.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-30990">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-40746 – IBM i Access Family 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.0 could allow ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-40746</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-40746</guid>
    <pubDate>Mon, 21 Nov 2022 18:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-40746</strong></p>
  <p>IBM i Access Family 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.0 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability. By placing a specially crafted file in a compromised folder, an attacker could exploit this vulnerability to execute arbitrary code on the system.  IBM X-Force ID:  236581.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-40746">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-22495 – IBM i 7.3, 7.4, and 7.5 is vulnerable to SQL injection. A remote attacker could ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-22495</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-22495</guid>
    <pubDate>Tue, 24 May 2022 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-22495</strong></p>
  <p>IBM i 7.3, 7.4, and 7.5 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 226941.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22495">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-20501 – IBM i 7.1, 7.2, 7.3, and 7.4 SMTP allows a network attacker to send emails to no...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-20501</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-20501</guid>
    <pubDate>Wed, 21 Apr 2021 12:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-20501</strong></p>
  <p>IBM i 7.1, 7.2, 7.3, and 7.4 SMTP allows a network attacker to send emails to non-existent local-domain recipients to the SMTP server, caused by using a non-default configuration. An attacker could exploit this vulnerability to consume unnecessary network bandwidth and disk space, and allow remote attackers to send spam email. IBM X-Force ID: 198056.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-20501">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-9412 – The file transfer component of TIBCO Software Inc.'s TIBCO Managed File Transfer...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9412</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9412</guid>
    <pubDate>Tue, 09 Jun 2020 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-9412</strong></p>
  <p>The file transfer component of TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server for IBM i contains a vulnerability that theoretically allows execution of arbitrary commands at the privilege level of the affected system following a failed file transfer. Affected releases are TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server for IBM i: versions 7.1.0 and below, vers…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9412">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-9411 – The file transfer component of TIBCO Software Inc.'s TIBCO Managed File Transfer...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9411</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9411</guid>
    <pubDate>Tue, 09 Jun 2020 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-9411</strong></p>
  <p>The file transfer component of TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server for IBM i contains a vulnerability that theoretically allows an attacker to perform unauthorized network file transfers to and from the file system accessible to the affected component. This vulnerability is exploitable when the configuration option 'Require Node Resp' is set to 'No'. In the event of…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9411">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-0114 – Stack-based buffer overflow in IBM V5R4, and IBM i Access for Windows 6.1 and 7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-0114</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-0114</guid>
    <pubDate>Mon, 28 Aug 2017 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-0114</strong></p>
  <p>Stack-based buffer overflow in IBM V5R4, and IBM i Access for Windows 6.1 and 7.1.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-0114">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-1460 – IBM i OSPF 6.1, 7.1, 7.2, and 7.3 is vulnerable when a rogue router spoofs its o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1460</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1460</guid>
    <pubDate>Mon, 31 Jul 2017 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-1460</strong></p>
  <p>IBM i OSPF 6.1, 7.1, 7.2, and 7.3 is vulnerable when a rogue router spoofs its origin. Routing tables are affected by a missing LSA, which may lead to loss of connectivity. IBM X-Force ID: 128379.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1460">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-11614 – MEDHOST Connex contains hard-coded credentials that are used for customer databa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-11614</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-11614</guid>
    <pubDate>Tue, 25 Jul 2017 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-11614</strong></p>
  <p>MEDHOST Connex contains hard-coded credentials that are used for customer database access. An attacker with knowledge of the hard-coded credentials and the ability to communicate directly with the database may be able to obtain or modify sensitive patient and financial information. Connex utilizes an IBM i DB2 user account for database access. The account name is HMSCXPDN. Its password is hard-co…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-11614">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-0287 – IBM i Access 7.1 on Windows allows local users to discover registry passwords vi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-0287</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-0287</guid>
    <pubDate>Fri, 08 Jul 2016 01:59:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-0287</strong></p>
  <p>IBM i Access 7.1 on Windows allows local users to discover registry passwords via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-0287">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-2023 – Buffer overflow in IBM i Access 7.1 on Windows allows local users to gain privil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-2023</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-2023</guid>
    <pubDate>Sat, 02 Jan 2016 21:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-2023</strong></p>
  <p>Buffer overflow in IBM i Access 7.1 on Windows allows local users to gain privileges via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-2023">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-8920 – Buffer overflow in the Data Transfer Program in IBM i Access 5770-XE1 5R4, 6.1, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-8920</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-8920</guid>
    <pubDate>Wed, 28 Jan 2015 22:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-8920</strong></p>
  <p>Buffer overflow in the Data Transfer Program in IBM i Access 5770-XE1 5R4, 6.1, and 7.1 on Windows allows local users to gain privileges via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-8920">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-5385 – The OSPF implementation in IBM i 6.1 and 7.1, in z/OS on zSeries servers, and in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-5385</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-5385</guid>
    <pubDate>Thu, 02 Jan 2014 14:59:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-5385</strong></p>
  <p>The OSPF implementation in IBM i 6.1 and 7.1, in z/OS on zSeries servers, and in Networking Operating System (aka NOS, formerly BLADE Operating System) does not properly validate Link State Advertisement (LSA) type 1 packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-5385">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
