CVE-2026-17111: IBM i is Affected By Multiple Vulnerabilities in SQL
IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
Other sources
IBM i is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM ito a version that resolves this vulnerability.Fixed in 7.6Patch SJ10867 - Upgrade
Upgrade
IBM ito a version that resolves this vulnerability.Fixed in 7.5Patch SJ10868 - Upgrade
Upgrade
IBM ito a version that resolves this vulnerability.Fixed in 7.4Patch SJ10869 - Upgrade
Upgrade
IBM ito a version that resolves this vulnerability.Fixed in 7.3Patch SJ10870
Event History
Frequently Asked Questions
What is the severity of CVE-2026-17111?
The severity of CVE-2026-17111 is rated as high, with a score of 7.6.
How does CVE-2026-17111 impact IBM i systems?
CVE-2026-17111 allows remote attackers to perform SQL injection, potentially enabling them to manipulate the back-end database.
How do I fix CVE-2026-17111?
To mitigate CVE-2026-17111, ensure that your IBM i system is updated to the latest patches provided by IBM.
What versions of IBM i are affected by CVE-2026-17111?
CVE-2026-17111 affects IBM i versions 7.6, 7.5, 7.4, and 7.3.
What type of attack is associated with CVE-2026-17111?
CVE-2026-17111 is associated with SQL injection attacks that can compromise data integrity and confidentiality.