Where
-Infinity
0
First published (updated )
Advisory
IBM-7287873
Severity
5.4
OS Command Injection
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to improper validation of FTP authentication commands.

1 / 2
Source: MITRE
First published (updated )
Severity
6.4
SSRF
AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions and access internal network services due to improper validation of FTP PORT and EPRT commands.

1 / 2
Source: MITRE
First published (updated )
First published (updated )
Advisory
IBM-7287408
Severity
6
Race Condition
AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to obtain ownership of arbitrary file system objects due to a time-of-check to time-of-use (TOCTOU) race condition.

1 / 2
Source: MITRE
First published (updated )
First published (updated )
Advisory
IBM-7287409
Severity
5.2
Buffer Overflow
AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a denial of service as a result of a buffer overflow in a PASE process. An authenticated attacker could leverage this to terminate their own process.

1 / 2
Source: MITRE
First published (updated )
Severity
3.3
Buffer Overflow
AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a denial of service as a result of a buffer overflow in a PASE process. An authenticated attacker could leverage this to terminate their own process.

1 / 2
Source: MITRE
First published (updated )
First published (updated )
Advisory
IBM-7286974
Severity
4.3
Path Traversal
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to place files into the file system with Navigator for i when they should be blocked by Navigator configuration. This could allow attackers to upload files onto the system to places the Navigator support did not intend, but only if the profile could already do that by itself.

1 / 2
Source: MITRE
First published (updated )
Severity
4.2
Race Condition
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a race condition during the WebSocket handshake process.

1 / 2
Source: MITRE
First published (updated )
Severity
5.3
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to gain access to sensitive information through session IP binding bypass in Navigator for i.

1 / 2
Source: MITRE
First published (updated )
Severity
4.3
AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to improper validation of the WebSocket origin.

1 / 2
Source: MITRE
First published (updated )
First published (updated )
Advisory
IBM-7286094
Severity
8.8
Integer Underflow
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to corrupt memory due to an integer underflow.

1 / 2
Source: MITRE
First published (updated )
First published (updated )
Advisory
IBM-7286186
Severity
8.1
AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipulate database transactions due to improper authorization in the DDM target dispatcher.

1 / 2
Source: MITRE
First published (updated )
Severity
9.8
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized access due to improper validation of client-supplied authentication parameters.

1 / 2
Source: MITRE
First published (updated )
First published (updated )
Advisory
IBM-7286093
Severity
7.5
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of the prefix length in ICMPv6 Router Advertisements.

1 / 2
Source: MITRE
First published (updated )
First published (updated )
Advisory
IBM-7283295
First published (updated )
Advisory
IBM-7285940
Severity
6.5
Infoleak
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to obtain sensitive information in PASE. An attacker could exploit this vulnerability to access information about process they shouldn't be permitted to access.

1 / 2
Source: MITRE
First published (updated )
First published (updated )
Advisory
IBM-7285938
Severity
5.5
AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

IBM i 7.6, and 7.5 could allow a local authenticated attacker to obtain information from a privileged file when using SSH.

1 / 2
Source: MITRE
First published (updated )
First published (updated )
Advisory
IBM-7285937
Severity
6.5
Integer Overflow
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to an integer overflow.

1 / 2
Source: MITRE
First published (updated )
First published (updated )
Advisory
IBM-7285939
Severity
7.5
Buffer Overflow
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a buffer overflow.

1 / 2
Source: MITRE
First published (updated )
Severity
5.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to an off-by-one write in the LPD queue name parser.

1 / 2
Source: MITRE
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203