Where
AND
-Infinity
0
Severity
8.8
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to privilege escalation via Navigator for i. An authenticated user could elevate privileges to a root user to execute commands.

1 / 2
Source: MITRE
First published (updated )
First published (updated )
Advisory
IBM-7269560
Severity
9.8
AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H

IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 s vulnerable to privilege escalation caused by an invalid IBM i Web Administration GUI authorization check.  A malicious actor could cause user-controlled code to run with administrator privilege.

1 / 2
Source: MITRE

Remedy

IBM strongly recommends addressing the vulnerability now. IBM i Release5770-DG1 PTF Number(s)PTF Download Link(s)7.6SJ08417 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ08417 7.5SJ08418 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ08418 7.4SJ08419 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ08419 7.3SJ08604 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ08604 7.2SJ08818 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ08818 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.
First published (updated )
Severity
8.8
AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 product IBM TCP/IP Connectivity Utilities for i contains a privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain root access to the host operating system.

1 / 2
Source: NVD

Remedy

The issue can be addressed by applying a PTF to IBM i. IBM i release 7.6, 7.5, 7.4, 7.3, 7.2 will be fixed. The IBM i 5770-TC1 PTF numbers listed below resolve the vulnerability. IBM i Release 5770-TC1 PTF Number PTF Download Link 7.6 SJ05513 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ05513 7.5 SJ05494 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ05494 7.4 SJ05505 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ05505 7.3 SJ05514 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ05514 7.2 SJ05525 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ05525
First published (updated )
Severity
8.8
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user to gain elevated privileges due to an unqualified library call in IBM Facsimile Support for i. A malicious actor could cause user-controlled code to run with administrator privilege.

1 / 2
Source: MITRE

Remedy

The issue can be fixed by applying a PTF to IBM i. IBM i 7.5, 7.4, 7.3, and 7.2 are addressed. The IBM i PTF number for 5798-FAX contains the fix for the vulnerability. 5798-FAX is a skip ship product installable on the listed releases. IBM i Release 5798-FAX  7.2 7.3 7.4 7.5 SJ06024 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ06024
First published (updated )
Severity
8.8
AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to a privilege escalation caused by an invalid database authority check. A bad actor could execute a database procedure or function without having all required permissions, in addition to causing denial of service for some database actions.

1 / 2
Source: MITRE

Remedy

The issue can be addressed by applying PTFs to IBM i. IBM i releases 7.6, 7.5, 7.4, 7.3. and 7.2 will be addressed. The IBM i 5770-SS1 PTF numbers listed below resolve the vulnerability. 7.6SJ05809 SJ05810 SJ05837 SJ05960 SJ06021 SJ06219 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ05809 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ05810 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ05837 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ05960 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ06021 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ06219 7.5SJ05838 SJ05847 SJ05850 SJ05851 SJ05953 SJ06022 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ05838 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ05847 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ05850 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ05851 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ05953 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ06022 7.4SJ05839 SJ05846 SJ05852 SJ05853 SJ05959 SJ06023 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ05839 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ05846 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ05852 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ05853 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ05959 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ06023 7.3SJ05840 SJ05845 SJ05854 SJ05855 SJ05966 SJ06477 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ05840 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ05845 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ05854 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ05855 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ05966 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ06477 7.2SJ05842 SJ05844 SJ05856 SJ05857 SJ05965 SJ06478 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ05842 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ05844 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ05856 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ05857 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ05965 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ06478
First published (updated )
Severity
8.8
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 is vulnerable to privilege escalation caused by an invalid IBM i SQL services authorization check. A malicious actor can use the elevated privileges of another user profile to gain root access to the host operating system.

1 / 2
Source: NVD

Remedy

Remediation/Fixes IBM strongly recommends addressing the vulnerability now. IBM i Release 5770-SS1 PTF Number(s) PTF Download Link(s) 7.6 SJ07552 SJ07650 SJ07651 SJ07652 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ07552 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ07650 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ07651 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ07652 7.5 SJ07553 SJ07653 SJ07654 SJ07655 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ07553 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ07653 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ07654 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ07655 7.4 SJ07554 SJ07656 SJ07657 SJ07658 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ07554 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ07656 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ07657 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ07658 7.3 SJ07555 SJ07659 SJ07660 SJ07661 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ07555 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ07659 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ07660 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ07661 7.2 SJ07556 SJ07662 SJ07663 SJ07664 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ07556 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ07662 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ07663 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ07664 IBM recommends that all users running unsupported versions of affected products upgrade to a supported version of the affected product.
First published (updated )
Severity
5.1
Infoleak
AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

A flaw was found in the Linux kernel. IBM Power9 processors can speculatively operate on data stored in the L1 cache before it has been completely validated. The attack has limited access to memory and is only able to access memory normally permissible to the execution context. The highest threat from this vulnerability is to data confidentiality.

1 / 7

Remedy

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
First published (updated )
Severity
5.1
AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

IBM AIX and VIOS information disclosure

1 / 2
First published (updated )
EOL
Apr 30, 2021

End of life: 4/30/2021, Latest version: 7.2.0

First published (updated )
EOL
Apr 30, 2021

End of life: 4/30/2021, Latest version: 7.2.0

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203