VYPR

I

by IBM

CVEs (110)

  • CVE-2026-17218CriAug 12, 2026
    risk 0.64cvss 9.8epss

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.

  • CVE-2026-16860CriAug 12, 2026
    risk 0.64cvss 9.9epss

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an uncontrolled search path element.

  • CVE-2026-17276CriAug 12, 2026
    risk 0.62cvss 9.6epss

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to escalate privileges due to improper authorization in the handling of high-authority threads.

  • CVE-2026-17223HigAug 13, 2026
    risk 0.57cvss 8.8epss

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to a buffer overflow.

  • CVE-2026-17029HigAug 13, 2026
    risk 0.57cvss 8.8epss

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code due to an out-of-bounds write.

  • CVE-2026-16975HigAug 13, 2026
    risk 0.57cvss 8.8epss

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to a heap-based buffer overflow.

  • CVE-2026-16722HigAug 13, 2026
    risk 0.57cvss 8.8epss

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain unauthorized privileges due to improper privilege management.

  • CVE-2026-18713HigAug 12, 2026
    risk 0.57cvss 8.8epss

    IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to privilege escalation via Navigator for i. An authenticated user could elevate privileges to a root user to execute commands.

  • CVE-2026-18669HigAug 12, 2026
    risk 0.57cvss 8.8epss

    IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to a privilege escalation as the result of a remote code execution vulnerability in the activation engine component. An authenticated attacker can execute a maliciously planted script with root authority.

  • CVE-2026-17110HigAug 12, 2026
    risk 0.57cvss 8.8epss

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands and obtain sensitive information due to improper privilege management.

  • CVE-2026-16906HigAug 12, 2026
    risk 0.57cvss 8.8epss

    IBM i 7.6, and 7.5 could allow a remote authenticated attacker to execute arbitrary commands with elevated privileges due to improper neutralization of special elements used in an OS command.

  • CVE-2026-16856HigAug 12, 2026
    risk 0.57cvss 8.8epss

    IBM i 7.6, and 7.5 could allow a local attacker to gain elevated privileges due to improper neutralization of special elements used in an OS command.

  • CVE-2026-7870HigJun 11, 2026
    risk 0.57cvss 8.8epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privilege.

  • CVE-2025-36367HigNov 1, 2025
    risk 0.57cvss 8.8epss 0.00

    IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 is vulnerable to privilege escalation caused by an invalid IBM i SQL services authorization check. A malicious actor can use the elevated privileges of another user profile to gain root access to the host operating system.

  • CVE-2025-36004HigJun 25, 2025
    risk 0.57cvss 8.8epss 0.01

    IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user to gain elevated privileges due to an unqualified library call in IBM Facsimile Support for i. A malicious actor could cause user-controlled code to run with administrator privilege.

  • CVE-2022-22495HigMay 24, 2022
    risk 0.57cvss 8.8epss 0.02

    IBM i 7.3, 7.4, and 7.5 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 226941.

  • CVE-2023-30990HigJul 4, 2023
    risk 0.56cvss 8.6epss 0.01

    IBM i 7.2, 7.3, 7.4, and 7.5 could allow a remote attacker to execute CL commands as QUSER, caused by an exploitation of DDM architecture. IBM X-Force ID: 254036.

  • CVE-2026-17418HigAug 12, 2026
    risk 0.55cvss 8.5epss

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to improper neutralization of special elements used in an SQL command.

  • CVE-2025-33108HigJun 14, 2025
    risk 0.55cvss 8.5epss 0.01

    IBM Backup, Recovery and Media Services for i 7.4 and 7.5 could allow a user with the capability to compile or restore a program to gain elevated privileges due to a library unqualified call made by a BRMS program. A malicious actor could cause user-controlled code to run with…

  • CVE-2025-33103HigMay 17, 2025
    risk 0.55cvss 8.5epss 0.00

    IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 product IBM TCP/IP Connectivity Utilities for i contains a privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain root access to the host operating system.

Page 1 of 6