IBM
IBM I: vulnerabilidades y CVE
IBM I tiene 203 vulnerabilidades publicadas, 148 de ellas en los últimos 12 meses. 21 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE203
Últimos 12 meses148
Críticas21
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-84414 | Alta (7.8) | 0.09% | — | 29 sept 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to change the ownership of arbitrary files due to improper validation of an attacker-controlled file path. |
| CVE-2026-18869 | Media (6.4) | 0.22% | — | 18 sept 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions and access internal network services due to improper validation of FTP PORT and EPRT commands. |
| CVE-2026-17262 | Media (5.4) | 0.19% | — | 18 sept 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to improper validation of FTP authentication commands. |
| CVE-2026-19280 | Media (5.2) | 0.12% | — | 14 sept 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a denial of service as a result of a buffer overflow in a PASE process. An authenticated attacker could leverage this to terminate their own process. |
| CVE-2026-19086 | Baja (3.3) | 0.12% | — | 14 sept 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a denial of service as a result of a buffer overflow in a PASE process. An authenticated attacker could leverage this to terminate their own process. |
| CVE-2026-18069 | Media (6) | 0.13% | — | 14 sept 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to obtain ownership of arbitrary file system objects due to a time-of-check to time-of-use (TOCTOU) race condition. |
| CVE-2026-18251 | Media (4.3) | 0.14% | — | 14 sept 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to improper validation of the WebSocket origin. |
| CVE-2026-18065 | Media (5.3) | 0.31% | — | 14 sept 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to gain access to sensitive information through session IP binding bypass in Navigator for i. |
| CVE-2026-18515 | Media (4.3) | 0.28% | — | 14 sept 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to place files into the file system with Navigator for i when they should be blocked by Navigator configuration. This could allow attackers to… |
| CVE-2026-18151 | Media (4.2) | 0.14% | — | 14 sept 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a race condition during the WebSocket handshake process. |
| CVE-2026-18341 | Alta (8.8) | 0.25% | — | 4 sept 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to corrupt memory due to an integer underflow. |
| CVE-2026-18221 | Crítica (9.8) | 0.34% | — | 4 sept 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized access due to improper validation of client-supplied authentication parameters. |
| CVE-2026-18175 | Alta (7.5) | 0.20% | — | 4 sept 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipulate database transactions due to improper authorization in the DDM target dispatcher. |
| CVE-2026-18078 | Media (6.5) | 0.29% | — | 4 sept 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to an integer overflow. |
| CVE-2026-18076 | Media (6.5) | 0.29% | — | 4 sept 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a memory leak. |
| CVE-2026-18073 | Media (4.4) | 0.10% | — | 4 sept 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to inject parameters into a CL command due to improper neutralization of special elements. |
| CVE-2026-17499 | Alta (7.8) | 0.12% | — | 4 sept 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. |
| CVE-2026-17470 | Alta (7.5) | 0.39% | — | 4 sept 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a buffer overflow. |
| CVE-2026-17469 | Media (5.5) | 0.21% | — | 4 sept 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to an off-by-one write in the LPD queue name parser. |
| CVE-2026-17274 | Media (5.4) | 0.24% | — | 4 sept 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to predictable server seeds. |
| CVE-2026-17273 | Media (6.5) | 0.35% | — | 4 sept 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a NULL pointer dereference. |
| CVE-2026-17270 | Media (5.5) | 0.21% | — | 4 sept 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to a stack-based buffer overflow. |
| CVE-2026-17259 | Media (6.5) | 0.36% | — | 4 sept 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a stack-based buffer overflow. |
| CVE-2026-17255 | Alta (7.5) | 0.40% | — | 4 sept 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of the prefix length in ICMPv6 Router Advertisements. |
| CVE-2026-17207 | Crítica (9.1) | 0.34% | — | 4 sept 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and compromise integrity due to a buffer overflow. |
| CVE-2026-17057 | Crítica (9.1) | 0.38% | — | 4 sept 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and affect data integrity due to missing authentication for critical functions. |
| CVE-2026-16941 | Media (4.3) | 0.22% | — | 4 sept 2026 | IBM i 7.6, 7.5, and 7.4 could allow a remote authenticated attacker to modify certain system messages due to improper authorization. |
| CVE-2026-16892 | Media (5.4) | 0.25% | — | 4 sept 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper authentication during service-name matching. |
| CVE-2026-16826 | Alta (7.8) | 0.13% | — | 4 sept 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. |
| CVE-2026-16693 | Media (4.9) | 0.13% | — | 4 sept 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to the use of hardcoded cryptographic constants to obfuscate encryption keys. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de IBM
AIX · 551Websphere Application Server · 519DB2 · 355Vios · 237Sterling B2B Integrator · 205Rational Quality Manager · 202Qradar Security Information AND Event Manager · 192Infosphere Information Server · 189Maximo Asset Management · 182Rational Doors Next Generation · 153Rational Team Concert · 142Rational Engineering Lifecycle Manager · 141