Vulnerability index

Browse CVEs

48 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
I HIGH 8.8
CVE-2026-16722

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain unauthorized privileges due to improper privilege management.

No fix yet
Fix from $4,900 2026-08-13
I HIGH 7.8
CVE-2026-18071

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper privilege management.

No fix yet
Fix from $4,900 2026-08-13
I HIGH 8.8
CVE-2026-17082

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improper validation of a client-supplied …

No fix yet
Fix from $4,900 2026-08-12
I HIGH 8.8
CVE-2026-18713

IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to privilege escalation via Navigator for i. An authenticated user could elevate privileges to a root user …

Fix: after 7.6
Fix from $4,900 2026-08-12
I CRITICAL 9.9
CVE-2026-17276

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to escalate privileges due to improper authorization in the handling of high…

Fix: after 7.6
Fix from $5,750 2026-08-12
I HIGH 8.1
CVE-2026-16904

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper privilege management during mo…

Fix: after 7.6
Fix from $4,900 2026-08-12
Websphere Application Server HIGH 8.8
CVE-2026-14980

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to per…

Fix: 26.0.0.9+
Fix from $1,950 2026-07-30
Turbonomic Prometurbo Agent HIGH 7.8
CVE-2026-6389

IBM Turbonomic prometurbo agent 8.16.0 through 8.17.6 IBM Turbonomic Application Resource Management grants excessive cluster‑wide permissions, inclu…

Fix: 8.18.0+
Fix from $1,950 2026-04-30
Websphere Application Server MEDIUM 5.9
CVE-2026-3621

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.4 IBM WebSphere Application Server Liberty is vulnerable to identity spoofing unde…

Fix: 26.0.0.5+
Fix from $1,600 2026-04-23
I HIGH 7.8
CVE-2024-27264

IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqualified library call. A malici…

Mitigation only
Fix from $1,950 2024-05-22
Security Verify Access HIGH 7.8
CVE-2023-31005

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 …

Fix: after 10.0.6.1
Fix from $1,950 2024-02-03
Merge Efilm Workstation HIGH 7.8
CVE-2024-23620

An improper privilege management vulnerability exists in IBM Merge Healthcare eFilm Workstation. A local, authenticated attacker can exploit this vul…

Fix: after 4.2
Fix from $1,950 2024-01-26
Db2 HIGH 7.8
CVE-2023-47145

IBM Db2 for Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow a local user to escalate their privileges to the SYSTEM user using…

Fix: 10.5.0.11 / 11.1.4.7+
Fix from $1,950 2024-01-07
Cics Tx HIGH 7.5
CVE-2023-43018

IBM CICS TX Standard 11.1 and Advanced 10.1, 11.1 performs an operation at a privilege level that is higher than the minimum level required, which cr…

Patch available
Fix from $1,950 2023-11-03
I HIGH 7.8
CVE-2023-40685

Management Central as part of IBM i 7.2, 7.3, 7.4, and 7.5 Navigator contains a local privilege escalation vulnerability. A malicious actor with com…

Patch available
Fix from $1,950 2023-10-29
I HIGH 7.8
CVE-2023-40686

Management Central as part of IBM i 7.2, 7.3, 7.4, and 7.5 Navigator contains a local privilege escalation vulnerability. A malicious actor with com…

Patch available
Fix from $1,950 2023-10-29
Hardware Management Console HIGH 7.8
CVE-2023-38280

IBM HMC (Hardware Management Console) 10.1.1010.0 and 10.2.1030.0 could allow a local user to escalate their privileges to root access on a restricte…

Patch available
Fix from $1,950 2023-10-16
I HIGH 7.8
CVE-2023-40377

Backup, Recovery, and Media Services (BRMS) for IBM i 7.2, 7.3, and 7.4 contains a local privilege escalation vulnerability. A malicious actor with …

Patch available
Fix from $1,950 2023-10-16
I HIGH 7.8
CVE-2023-40378

IBM Directory Server for IBM i contains a local privilege escalation vulnerability. A malicious actor with command line access to the host operating…

Patch available
Fix from $1,950 2023-10-15
I HIGH 7.8
CVE-2023-40375

Integrated application server for IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability. A malicious actor with command l…

Patch available
Fix from $1,950 2023-09-28
Robotic Process Automation CRITICAL 9.8
CVE-2023-38734

IBM Robotic Process Automation 21.0.0 through 21.0.7.1 and 23.0.0 through 23.0.1 is vulnerable to incorrect privilege assignment when importing users…

Fix: after 21.0.7.1
Fix from $2,300 2023-08-22
I HIGH 7.8
CVE-2023-38721

The IBM i 7.2, 7.3, 7.4, and 7.5 product Facsimile Support for i contains a local privilege escalation vulnerability. A malicious actor could gain …

Patch available
Fix from $1,950 2023-08-14
I HIGH 7.8
CVE-2023-30988

The IBM i 7.2, 7.3, 7.4, and 7.5 product Facsimile Support for i contains a local privilege escalation vulnerability. A malicious actor with command…

Patch available
Fix from $1,950 2023-07-16
I HIGH 7.8
CVE-2023-30989

IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability. A malicious actor with command line access t…

Patch available
Fix from $1,950 2023-07-16
Db2 HIGH 7.8
CVE-2023-27558

IBM Db2 on Windows 10.5, 11.1, and 11.5 may be vulnerable to a privilege escalation caused by at least one installed service using an unquoted servic…

Patch available
Fix from $1,950 2023-07-10
Db2 MEDIUM 6.5
CVE-2023-29256

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to an information disclosure due to improper pri…

Mitigation only
Fix from $1,600 2023-07-10
Qradar Security Information And Event Manager HIGH 7.2
CVE-2022-43863

IBM QRadar SIEM 7.4 and 7.5 is vulnerable to privilege escalation, allowing a user with some admin capabilities to gain additional admin capabilities…

Fix: 7.4.3+
Fix from $1,950 2023-03-22
Db2 HIGH 7.5
CVE-2022-43927

IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to information Disclosure due to improper privilege management when a speciall…

Patch available
Fix from $1,950 2023-02-17
Vios HIGH 8.4
CVE-2022-41290

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the rm_rlcache_file command to obtain root …

Patch available
Fix from $1,950 2022-12-23
Db2 MEDIUM 6.5
CVE-2022-22483

IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to an information disclosure in some scenarios due to unauthorized …

Patch available
Fix from $1,600 2022-09-13