<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – IBM iSeries</title>
  <link>https://cvedaily.com/pages/tags/ibm-i.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/ibm-i.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – IBM iSeries</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:35 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-7770 – IBM i Access Family 1.1.5.0 through 1.1.9.12 IBM i Access Client Solutions (ACS)...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7770</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7770</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7770</strong></p>
  <p>IBM i Access Family 1.1.5.0 through 1.1.9.12 IBM i Access Client Solutions (ACS) is vulnerable to remote code execution when configured to listen for requests from IBM i Navigator.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7770">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6936 – IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to a denial-of-service attack due to u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6936</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6936</guid>
    <pubDate>Wed, 27 May 2026 14:17:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6936</strong></p>
  <p>IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to a denial-of-service attack due to uncontrolled recursion in the Integrated Language Environment (ILE) compiler. An authenticated attacker could exploit this vulnerability by compiling specially crafted source code containing a specific combination of statements.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-674</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6936">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-2311 – IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 s vulnerable to privilege escalation caused by...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2311</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2311</guid>
    <pubDate>Thu, 30 Apr 2026 22:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-2311</strong></p>
  <p>IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 s vulnerable to privilege escalation caused by an invalid IBM i Web Administration GUI authorization check.  A malicious actor could cause user-controlled code to run with administrator privilege.</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2311">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1376 – IBM i 7.6 could allow a remote attacker to cause a denial of service using faile...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1376</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1376</guid>
    <pubDate>Tue, 17 Mar 2026 22:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1376</strong></p>
  <p>IBM i 7.6 could allow a remote attacker to cause a denial of service using failed authentication connections due to improper allocation of resources.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1376">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-36371 – IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 are impacted by obtaining an information vulne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36371</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36371</guid>
    <pubDate>Wed, 19 Nov 2025 20:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-36371</strong></p>
  <p>IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 are impacted by obtaining an information vulnerability in the database plan cache implementation.  A user with access to the database plan cache could see information they do not have authority to view.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-598</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36371">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-36367 – IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 is vulnerable to privilege escalation caused b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36367</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36367</guid>
    <pubDate>Sat, 01 Nov 2025 12:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-36367</strong></p>
  <p>IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 is vulnerable to privilege escalation caused by an invalid IBM i SQL services authorization check. A malicious actor can use the elevated privileges of another user profile to gain root access to the host operating system.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36367">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-36035 – IBM PowerVM Hypervisor FW950.00 through FW950.E0, FW1050.00 through FW1050.50, a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36035</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36035</guid>
    <pubDate>Sun, 14 Sep 2025 13:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-36035</strong></p>
  <p>IBM PowerVM Hypervisor FW950.00 through FW950.E0, FW1050.00 through FW1050.50, and FW1060.00 through FW1060.40 could allow a local privileged user to cause a denial of service by issuing a specially crafted IBM i hypervisor call that would disclose memory contents or consume excessive memory resources.</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36035">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-42958 – Due to a missing authentication check in the SAP NetWeaver application on IBM i-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-42958</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-42958</guid>
    <pubDate>Tue, 09 Sep 2025 02:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-42958</strong></p>
  <p>Due to a missing authentication check in the SAP NetWeaver application on IBM i-series, the application allows high privileged unauthorized users to read, modify, or delete sensitive information, as well as access administrative or privileged functionalities. This results in a high impact on the confidentiality, integrity, and availability of the application.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-42958">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-36119 – IBM i 7.3, 7.4, 7.5, and 7.6 is affected by an authenticated user obtaining elev...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36119</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36119</guid>
    <pubDate>Fri, 08 Aug 2025 15:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-36119</strong></p>
  <p>IBM i 7.3, 7.4, 7.5, and 7.6 is affected by an authenticated user obtaining elevated privileges with IBM Digital Certificate Manager for i (DCM) due to a web session hijacking vulnerability. An authenticated user without administrator privileges could exploit this vulnerability to perform actions in DCM as an administrator.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36119">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-33109 – IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to a privilege escalation caused...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-33109</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-33109</guid>
    <pubDate>Thu, 24 Jul 2025 15:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-33109</strong></p>
  <p>IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to a privilege escalation caused by an invalid database authority check.  A bad actor could execute a database procedure or function without having all required permissions, in addition to causing denial of service for some database actions.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-33109">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-36004 – IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user to gain elevated privileges due ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36004</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36004</guid>
    <pubDate>Wed, 25 Jun 2025 03:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-36004</strong></p>
  <p>IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user to gain elevated privileges due to an unqualified library call in IBM Facsimile Support for i. A malicious actor could cause user-controlled code to run with administrator privilege.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36004">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-33122 – IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 could allow a user to gain elevated privileges...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-33122</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-33122</guid>
    <pubDate>Tue, 17 Jun 2025 18:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-33122</strong></p>
  <p>IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 could allow a user to gain elevated privileges due to an unqualified library call in IBM Advanced Job Scheduler for i. A malicious actor could cause user-controlled code to run with administrator privilege.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-33122">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-33103 – IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 product IBM TCP/IP Connectivity Utilities for ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-33103</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-33103</guid>
    <pubDate>Sat, 17 May 2025 16:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-33103</strong></p>
  <p>IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 product IBM TCP/IP Connectivity Utilities for i contains a privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain root access to the host operating system.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-33103">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-3218 – IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to authentication and authorizat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3218</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3218</guid>
    <pubDate>Wed, 07 May 2025 02:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-3218</strong></p>
  <p>IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to authentication and authorization attacks due to incorrect validation processing in IBM i Netserver.  A malicious actor could use the weaknesses, in conjunction with brute force authentication attacks or to bypass authority restrictions, to access the server.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3218">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-2950 – IBM i 7.3, 7.4, 7.5, and 7.5 is vulnerable to a host header injection attack cau...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2950</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2950</guid>
    <pubDate>Fri, 18 Apr 2025 15:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-2950</strong></p>
  <p>IBM i 7.3, 7.4, 7.5, and 7.5 is vulnerable to a host header injection attack caused by improper neutralization of HTTP header content by IBM Navigator for i. An authenticated user can manipulate the host header in HTTP requests to change domain/IP address which may lead to unexpected behavior.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-644</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2950">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-2947 – IBM i 7.6 

contains a privilege escalation vulnerability due to incorrect profi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2947</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2947</guid>
    <pubDate>Thu, 17 Apr 2025 17:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-2947</strong></p>
  <p>IBM i 7.6   contains a privilege escalation vulnerability due to incorrect profile swapping in an OS command.  A malicious actor can use the command to elevate privileges to gain root access to the host operating system.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-278</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2947">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-55898 – IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user with the capability to compile o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-55898</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-55898</guid>
    <pubDate>Mon, 24 Feb 2025 02:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-55898</strong></p>
  <p>IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user with the capability to compile or restore a program to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privilege.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-55898">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-52895 – IBM i 7.4 and 7.5 is vulnerable to a database access denial of service caused by...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52895</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52895</guid>
    <pubDate>Fri, 14 Feb 2025 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-52895</strong></p>
  <p>IBM i 7.4 and 7.5 is vulnerable to a database access denial of service caused by a bypass of a database capabilities restriction check. A privileged bad actor can remove or otherwise impact database infrastructure files resulting in incorrect behavior of software products that rely upon the database.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52895">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-35122 – IBM i 7.2, 7.3, 7.4, and 7.5 is vulnerable to a file level local denial of servi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35122</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35122</guid>
    <pubDate>Fri, 24 Jan 2025 18:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-35122</strong></p>
  <p>IBM i 7.2, 7.3, 7.4, and 7.5 is vulnerable to a file level local denial of service caused by an insufficient authority requirement. A local non-privileged user can configure a referential constraint with the privileges of a user socially engineered to access the target file.</p>
  <p><strong>CVSS:</strong> 2.8 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35122">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-51464 – IBM i 7.3, 7.4, and 7.5 is vulnerable to bypassing Navigator for i interface res...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51464</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51464</guid>
    <pubDate>Sat, 21 Dec 2024 14:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-51464</strong></p>
  <p>IBM i 7.3, 7.4, and 7.5 is vulnerable to bypassing Navigator for i interface restrictions.  By sending a specially crafted request, an authenticated attacker could exploit this vulnerability to remotely perform operations that the user is not allowed to perform when using Navigator for i.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51464">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-51463 – IBM i 7.3, 7.4, and 7.5 

is vulnerable to server-side request forgery (SSRF). T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51463</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51463</guid>
    <pubDate>Sat, 21 Dec 2024 14:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-51463</strong></p>
  <p>IBM i 7.3, 7.4, and 7.5   is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51463">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-47104 – IBM i 7.4 and 7.5 is vulnerable to an authenticated user gaining elevated privil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47104</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47104</guid>
    <pubDate>Wed, 18 Dec 2024 11:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-47104</strong></p>
  <p>IBM i 7.4 and 7.5 is vulnerable to an authenticated user gaining elevated privilege to a physical file. A user with authority to a view can alter the based-on physical file security attributes without having object management rights to the physical file. A malicious actor can use the elevated privileges to perform actions restricted by their view privileges.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47104">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-31890 – IBM i 7.3, 7.4, and 7.5 product IBM TCP/IP Connectivity Utilities for i contains...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-31890</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-31890</guid>
    <pubDate>Fri, 21 Jun 2024 10:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-31890</strong></p>
  <p>IBM i 7.3, 7.4, and 7.5 product IBM TCP/IP Connectivity Utilities for i contains a local privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain root access to the host operating system.  IBM X-Force ID:  288171.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-31890">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-27275 – IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-27275</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-27275</guid>
    <pubDate>Sat, 15 Jun 2024 14:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-27275</strong></p>
  <p>IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability caused by an insufficient authority requirement. A local user without administrator privilege can configure a physical file trigger to execute with the privileges of a user socially engineered to access the target file. The correction is to require administrator privilege to configure trigger support.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27275">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-31878 – IBM i 7.2, 7.3, 7.4, and 7.5 Service Tools Server (SST) is vulnerable to SST use...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-31878</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-31878</guid>
    <pubDate>Fri, 07 Jun 2024 14:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-31878</strong></p>
  <p>IBM i 7.2, 7.3, 7.4, and 7.5 Service Tools Server (SST) is vulnerable to SST user enumeration by a remote attacker.  This vulnerability can be used by a malicious actor to gather information about SST users that can be targeted in further attacks.   IBM X-Force ID:  287538.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-203</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-31878">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-31879 – IBM i 7.2, 7.3, and 7.4 could allow a remote attacker to execute arbitrary code ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-31879</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-31879</guid>
    <pubDate>Sat, 18 May 2024 16:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-31879</strong></p>
  <p>IBM i 7.2, 7.3, and 7.4 could allow a remote attacker to execute arbitrary code leading to a denial of service of network ports on the system, caused by the deserialization of untrusted data.  IBM X-Force ID:  287539.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-31879">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-25050 – IBM i 7.2, 7.3, 7.4, 7.5 and IBM Rational Development Studio for i 7.2, 7.3, 7.4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-25050</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-25050</guid>
    <pubDate>Sun, 28 Apr 2024 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-25050</strong></p>
  <p>IBM i 7.2, 7.3, 7.4, 7.5 and IBM Rational Development Studio for i 7.2, 7.3, 7.4, 7.5 networking and compiler infrastructure could allow a local user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privileges.  IBM X-Force ID:  283242.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-25050">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22346 – Db2 for IBM i 7.2, 7.3, 7.4, and 7.5 infrastructure could allow a local user to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22346</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22346</guid>
    <pubDate>Thu, 14 Mar 2024 19:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22346</strong></p>
  <p>Db2 for IBM i 7.2, 7.3, 7.4, and 7.5 infrastructure could allow a local user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privilege.  IBM X-Force ID:  280203.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22346">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-22318 – IBM i Access Client Solutions (ACS) 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22318</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22318</guid>
    <pubDate>Fri, 09 Feb 2024 01:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-22318</strong></p>
  <p>IBM i Access Client Solutions (ACS) 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.4 is vulnerable to NT LAN Manager (NTLM) hash disclosure by an attacker modifying UNC capable paths within ACS configuration files to point to a hostile server. If NTLM is enabled, the Windows operating system will try to authenticate using the current user's session. The hostile server could capture the NTLM hash i…</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22318">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-43064 – Facsimile Support for IBM i 7.2, 7.3, 7.4, and 7.5 could allow a local user to g...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-43064</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-43064</guid>
    <pubDate>Mon, 25 Dec 2023 03:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-43064</strong></p>
  <p>Facsimile Support for IBM i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqualified library call.  A malicious actor could cause arbitrary code to run with the privilege of the user invoking the facsimile support.  IBM X-Force ID:  267689.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-43064">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-47741 – IBM i 7.3, 7.4, 7.5, IBM i Db2 Mirror for i 7.4 and 7.5 web browser clients may ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-47741</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-47741</guid>
    <pubDate>Mon, 18 Dec 2023 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-47741</strong></p>
  <p>IBM i 7.3, 7.4, 7.5, IBM i Db2 Mirror for i 7.4 and 7.5 web browser clients may leave clear-text passwords in browser memory that can be viewed using common browser tools before the memory is garbage collected. A malicious actor with access to the victim's PC could exploit this vulnerability to gain access to the IBM i operating system. IBM X-Force ID: 272532.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-47741">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-45185 – IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-45185</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-45185</guid>
    <pubDate>Thu, 14 Dec 2023 14:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-45185</strong></p>
  <p>IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an attacker to execute remote code.  Due to improper authority checks the attacker could perform operations on the PC under the user's authority.  IBM X-Force ID:  268273.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45185">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-45182 – IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-45182</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-45182</guid>
    <pubDate>Thu, 14 Dec 2023 14:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-45182</strong></p>
  <p>IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 is vulnerable to having its key for an encrypted password decoded. By somehow gaining access to the encrypted password, a local attacker could exploit this vulnerability to obtain the password to other systems. IBM X-Force ID: 268265.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-922</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45182">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-45184 – IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-45184</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-45184</guid>
    <pubDate>Thu, 14 Dec 2023 02:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-45184</strong></p>
  <p>IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an attacker to obtain a decryption key due to improper authority checks.  IBM X-Force ID:  268270.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-922</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45184">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-40685 – Management Central as part of IBM i 7.2, 7.3, 7.4, and 7.5 Navigator contains a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40685</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40685</guid>
    <pubDate>Sun, 29 Oct 2023 02:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-40685</strong></p>
  <p>Management Central as part of IBM i 7.2, 7.3, 7.4, and 7.5 Navigator contains a local privilege escalation vulnerability.  A malicious actor with command line access to the operating system can exploit this vulnerability to elevate privileges to gain root access to the operating system.  IBM X-Force ID:  264116.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40685">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-40686 – Management Central as part of IBM i 7.2, 7.3, 7.4, and 7.5 Navigator contains a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40686</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40686</guid>
    <pubDate>Sun, 29 Oct 2023 01:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-40686</strong></p>
  <p>Management Central as part of IBM i 7.2, 7.3, 7.4, and 7.5 Navigator contains a local privilege escalation vulnerability.  A malicious actor with command line access to the operating system can exploit this vulnerability to elevate privileges to gain component access to the operating system.  IBM X-Force ID:  264114.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40686">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-40377 – Backup, Recovery, and Media Services (BRMS) for IBM i 7.2, 7.3, and 7.4 contains...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40377</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40377</guid>
    <pubDate>Mon, 16 Oct 2023 01:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-40377</strong></p>
  <p>Backup, Recovery, and Media Services (BRMS) for IBM i 7.2, 7.3, and 7.4 contains a local privilege escalation vulnerability.  A malicious actor with command line access to the host operating system can elevate privileges to gain component access to the host operating system.  IBM X-Force ID:  263583.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40377">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-40378 – IBM Directory Server for IBM i contains a local privilege escalation vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40378</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40378</guid>
    <pubDate>Sun, 15 Oct 2023 02:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-40378</strong></p>
  <p>IBM Directory Server for IBM i contains a local privilege escalation vulnerability.  A malicious actor with command line access to the host operating system can elevate privileges to gain component access to the host operating system.  IBM X-Force ID:  263584.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40378">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-40375 – Integrated application server for IBM i 7.2, 7.3, 7.4, and 7.5 contains a local ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40375</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40375</guid>
    <pubDate>Thu, 28 Sep 2023 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-40375</strong></p>
  <p>Integrated application server for IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability.  A malicious actor with command line access to the host operating system can elevate privileges to gain root access to the host operating system.  IBM X-Force ID:  263580.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40375">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-38721 – The IBM i 7.2, 7.3, 7.4, and 7.5 product Facsimile Support for i contains a loca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38721</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38721</guid>
    <pubDate>Mon, 14 Aug 2023 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-38721</strong></p>
  <p>The IBM i 7.2, 7.3, 7.4, and 7.5 product Facsimile Support for i contains a local privilege escalation vulnerability.   A malicious actor could gain access to a command line with elevated privileges allowing root access to the host operating system.  IBM X-Force ID:  262173.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38721">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-30988 – The IBM i 7.2, 7.3, 7.4, and 7.5 product Facsimile Support for i contains a loca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-30988</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-30988</guid>
    <pubDate>Sun, 16 Jul 2023 23:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-30988</strong></p>
  <p>The IBM i 7.2, 7.3, 7.4, and 7.5 product Facsimile Support for i contains a local privilege escalation vulnerability.  A malicious actor with command line access to the host operating system can elevate privileges to gain root access to the host operating system.  IBM X-Force ID:  254016.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-30988">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-30990 – IBM i 7.2, 7.3, 7.4, and 7.5 could allow a remote attacker to execute CL command...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-30990</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-30990</guid>
    <pubDate>Tue, 04 Jul 2023 00:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-30990</strong></p>
  <p>IBM i 7.2, 7.3, 7.4, and 7.5 could allow a remote attacker to execute CL commands as QUSER, caused by an exploitation of DDM architecture.  IBM X-Force ID:  254036.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-30990">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-23470 – IBM i 7.2, 7.3, 7.4, and 7.5 could allow an authenticated privileged administrat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-23470</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-23470</guid>
    <pubDate>Thu, 04 May 2023 14:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-23470</strong></p>
  <p>IBM i 7.2, 7.3, 7.4, and 7.5 could allow an authenticated privileged administrator to gain elevated privileges in non-default configurations, as a result of improper SQL processing. By using a specially crafted SQL operation, the administrator could exploit the vulnerability to perform additional administrator operations.  IBM X-Force ID:  244510.</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-23470">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-40746 – IBM i Access Family 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.0 could allow ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-40746</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-40746</guid>
    <pubDate>Mon, 21 Nov 2022 18:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-40746</strong></p>
  <p>IBM i Access Family 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.0 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability. By placing a specially crafted file in a compromised folder, an attacker could exploit this vulnerability to execute arbitrary code on the system.  IBM X-Force ID:  236581.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-40746">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-34358 – IBM i 7.2, 7.3, 7.4, and 7.5 is vulnerable to cross-site scripting. This vulnera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-34358</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-34358</guid>
    <pubDate>Wed, 13 Jul 2022 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-34358</strong></p>
  <p>IBM i 7.2, 7.3, 7.4, and 7.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 230516.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-34358">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-22495 – IBM i 7.3, 7.4, and 7.5 is vulnerable to SQL injection. A remote attacker could ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-22495</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-22495</guid>
    <pubDate>Tue, 24 May 2022 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-22495</strong></p>
  <p>IBM i 7.3, 7.4, and 7.5 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 226941.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22495">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-39056 – The IBM i 7.1, 7.2, 7.3, and 7.4 Extended Dynamic Remote SQL server (EDRSQL) cou...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-39056</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-39056</guid>
    <pubDate>Thu, 13 Jan 2022 18:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-39056</strong></p>
  <p>The IBM i 7.1, 7.2, 7.3, and 7.4 Extended Dynamic Remote SQL server (EDRSQL) could allow a remote authenticated user to send a specially crafted request and cause a denial of service. IBM X-Force ID: 214537.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39056">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-38876 – IBM i 7.2, 7.3, and 7.4 is vulnerable to cross-site scripting. This vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38876</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38876</guid>
    <pubDate>Thu, 30 Dec 2021 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-38876</strong></p>
  <p>IBM i 7.2, 7.3, and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 208404.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38876">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-38937 – IBM PowerVM Hypervisor FW940, FW950, and FW1010 could allow an authenticated use...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38937</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38937</guid>
    <pubDate>Fri, 10 Dec 2021 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-38937</strong></p>
  <p>IBM PowerVM Hypervisor FW940, FW950, and FW1010 could allow an authenticated user to cause the system to crash using a specially crafted IBMi Hypervisor call. IBM X-Force ID: 210894.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38937">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-20501 – IBM i 7.1, 7.2, 7.3, and 7.4 SMTP allows a network attacker to send emails to no...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-20501</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-20501</guid>
    <pubDate>Wed, 21 Apr 2021 12:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-20501</strong></p>
  <p>IBM i 7.1, 7.2, 7.3, and 7.4 SMTP allows a network attacker to send emails to non-existent local-domain recipients to the SMTP server, caused by using a non-default configuration. An attacker could exploit this vulnerability to consume unnecessary network bandwidth and disk space, and allow remote attackers to send spam email. IBM X-Force ID: 198056.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-20501">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-9412 – The file transfer component of TIBCO Software Inc.'s TIBCO Managed File Transfer...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9412</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9412</guid>
    <pubDate>Tue, 09 Jun 2020 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-9412</strong></p>
  <p>The file transfer component of TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server for IBM i contains a vulnerability that theoretically allows execution of arbitrary commands at the privilege level of the affected system following a failed file transfer. Affected releases are TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server for IBM i: versions 7.1.0 and below, vers…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9412">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-9411 – The file transfer component of TIBCO Software Inc.'s TIBCO Managed File Transfer...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9411</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9411</guid>
    <pubDate>Tue, 09 Jun 2020 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-9411</strong></p>
  <p>The file transfer component of TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server for IBM i contains a vulnerability that theoretically allows an attacker to perform unauthorized network file transfers to and from the file system accessible to the affected component. This vulnerability is exploitable when the configuration option 'Require Node Resp' is set to 'No'. In the event of…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9411">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2020-4345 – IBM i 7.2, 7.3, and 7.4 users running complex SQL statements under a specific se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4345</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4345</guid>
    <pubDate>Sun, 17 May 2020 14:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2020-4345</strong></p>
  <p>IBM i 7.2, 7.3, and 7.4 users running complex SQL statements under a specific set of circumstances may allow a local user to obtain sensitive information that they should not have access to. IBM X-Force ID: 178318.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4345">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-4450 – IBM i 7.2, 7.3, and 7.4 for i is vulnerable to cross-site scripting. This vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-4450</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-4450</guid>
    <pubDate>Sat, 09 Nov 2019 02:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-4450</strong></p>
  <p>IBM i 7.2, 7.3, and 7.4 for i is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 163492.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-4450">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-4536 – IBM i 7.4 users who have done a Restore User Profile (RSTUSRPRF) on a system whi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-4536</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-4536</guid>
    <pubDate>Thu, 29 Aug 2019 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-4536</strong></p>
  <p>IBM i 7.4 users who have done a Restore User Profile (RSTUSRPRF) on a system which has been configured with Db2 Mirror for i might have user profiles with elevated privileges caused by incorrect processing during a restore of multiple user profiles. A user with restore privileges could exploit this vulnerability to obtain elevated privileges on the restored system. IBM X-Force ID: 165592.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-4536">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-4381 – IBM i 7.27.3 Clustering could allow a local attacker to obtain sensitive informa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-4381</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-4381</guid>
    <pubDate>Fri, 14 Jun 2019 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-4381</strong></p>
  <p>IBM i 7.27.3 Clustering could allow a local attacker to obtain sensitive information, caused by the use of advanced node failure detection using the REST API to interface with the HMC. An attacker could exploit this vulnerability to obtain HMC credentials. IBM X-Force ID: 162159.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-255</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-4381">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-4040 – IBM I 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-4040</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-4040</guid>
    <pubDate>Thu, 31 Jan 2019 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-4040</strong></p>
  <p>IBM I 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 156164.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-4040">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-1888 – An untrusted search path vulnerability in IBM i Access for Windows versions 7.1 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1888</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1888</guid>
    <pubDate>Fri, 04 Jan 2019 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-1888</strong></p>
  <p>An untrusted search path vulnerability in IBM i Access for Windows versions 7.1 and earlier on Windows can allow arbitrary code execution via a Trojan horse DLL in the current working directory, related to use of the LoadLibrary function. IBM X-Force ID: 152079.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-426</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1888">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-0114 – Stack-based buffer overflow in IBM V5R4, and IBM i Access for Windows 6.1 and 7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-0114</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-0114</guid>
    <pubDate>Mon, 28 Aug 2017 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-0114</strong></p>
  <p>Stack-based buffer overflow in IBM V5R4, and IBM i Access for Windows 6.1 and 7.1.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-0114">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-1460 – IBM i OSPF 6.1, 7.1, 7.2, and 7.3 is vulnerable when a rogue router spoofs its o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1460</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1460</guid>
    <pubDate>Mon, 31 Jul 2017 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-1460</strong></p>
  <p>IBM i OSPF 6.1, 7.1, 7.2, and 7.3 is vulnerable when a rogue router spoofs its origin. Routing tables are affected by a missing LSA, which may lead to loss of connectivity. IBM X-Force ID: 128379.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1460">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-11614 – MEDHOST Connex contains hard-coded credentials that are used for customer databa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-11614</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-11614</guid>
    <pubDate>Tue, 25 Jul 2017 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-11614</strong></p>
  <p>MEDHOST Connex contains hard-coded credentials that are used for customer database access. An attacker with knowledge of the hard-coded credentials and the ability to communicate directly with the database may be able to obtain or modify sensitive patient and financial information. Connex utilizes an IBM i DB2 user account for database access. The account name is HMSCXPDN. Its password is hard-co…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-11614">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-0287 – IBM i Access 7.1 on Windows allows local users to discover registry passwords vi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-0287</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-0287</guid>
    <pubDate>Fri, 08 Jul 2016 01:59:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-0287</strong></p>
  <p>IBM i Access 7.1 on Windows allows local users to discover registry passwords via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-0287">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-7462 – IBM WebSphere MQ 8.0.0.4 on IBM i platforms allows local users to discover clear...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-7462</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-7462</guid>
    <pubDate>Sun, 19 Jun 2016 20:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-7462</strong></p>
  <p>IBM WebSphere MQ 8.0.0.4 on IBM i platforms allows local users to discover cleartext certificate-keystore passwords within MQ trace output by leveraging administrator privileges to execute the mqcertck program.</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-7462">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-7422 – Buffer overflow in IBM i Access 7.1 on Windows allows local users to cause a den...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-7422</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-7422</guid>
    <pubDate>Sat, 02 Jan 2016 21:59:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-7422</strong></p>
  <p>Buffer overflow in IBM i Access 7.1 on Windows allows local users to cause a denial of service (application crash) via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-7422">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-7416 – AFP Workbench Viewer in IBM i Access 7.1 on Windows allows remote attackers to c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-7416</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-7416</guid>
    <pubDate>Sat, 02 Jan 2016 21:59:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-7416</strong></p>
  <p>AFP Workbench Viewer in IBM i Access 7.1 on Windows allows remote attackers to cause a denial of service (viewer crash) via a crafted workbench file.</p>
  <p><strong>CVSS:</strong> 4.0 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-7416">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-2023 – Buffer overflow in IBM i Access 7.1 on Windows allows local users to gain privil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-2023</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-2023</guid>
    <pubDate>Sat, 02 Jan 2016 21:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-2023</strong></p>
  <p>Buffer overflow in IBM i Access 7.1 on Windows allows local users to gain privileges via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-2023">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-1909 – The XML parser in the Reference Data Management component in the server in IBM I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-1909</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-1909</guid>
    <pubDate>Mon, 25 May 2015 00:59:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-1909</strong></p>
  <p>The XML parser in the Reference Data Management component in the server in IBM InfoSphere Master Data Management (MDM) 10.1 before IF1, 11.0 before FP3, 11.3, and 11.4 before FP2 allows remote attackers to read arbitrary files, and consequently obtain administrative access, via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-1909">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-8920 – Buffer overflow in the Data Transfer Program in IBM i Access 5770-XE1 5R4, 6.1, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-8920</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-8920</guid>
    <pubDate>Wed, 28 Jan 2015 22:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-8920</strong></p>
  <p>Buffer overflow in the Data Transfer Program in IBM i Access 5770-XE1 5R4, 6.1, and 7.1 on Windows allows local users to gain privileges via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-8920">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-5385 – The OSPF implementation in IBM i 6.1 and 7.1, in z/OS on zSeries servers, and in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-5385</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-5385</guid>
    <pubDate>Thu, 02 Jan 2014 14:59:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-5385</strong></p>
  <p>The OSPF implementation in IBM i 6.1 and 7.1, in z/OS on zSeries servers, and in Networking Operating System (aka NOS, formerly BLADE Operating System) does not properly validate Link State Advertisement (LSA) type 1 packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-5385">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-1376 – iscdeploy in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.43, 7.0 bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-1376</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-1376</guid>
    <pubDate>Thu, 19 Jan 2012 11:55:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-1376</strong></p>
  <p>iscdeploy in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.43, 7.0 before 7.0.0.21, and 8.0 before 8.0.0.2 on the IBM i platform sets weak permissions under systemapps/isclite.ear/ and bin/client_ffdc/, which allows local users to read or modify files via standard filesystem operations.</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-1376">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2005-1133 – The POP3 server in IBM iSeries AS/400 returns different error messages when the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-1133</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-1133</guid>
    <pubDate>Mon, 02 May 2005 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2005-1133</strong></p>
  <p>The POP3 server in IBM iSeries AS/400 returns different error messages when the user exists or not, which allows remote attackers to determine valid user IDs on the server.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-1133">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
