Vulnerability index

Browse CVEs

20 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Search Path (DLL Hijack)CWE-427 × clear
I CRITICAL 9.9
CVE-2026-16860

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an uncontrolled search path element.

Fix: after 7.6
Fix from $5,750 2026-08-12
I HIGH 8.8
CVE-2026-7870

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-co…

Mitigation only
Fix from $1,950 2026-06-11
Trusteer Rapport HIGH 7.8
CVE-2026-2713

IBM Trusteer Rapport installer 3.5.2309.290 IBM Trusteer Rapport could allow a local attacker to execute arbitrary code on the system, caused by DLL …

Mitigation only
Fix from $1,950 2026-03-10
I HIGH 8.8
CVE-2025-36004

IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user to gain elevated privileges due to an unqualified library call in IBM Facsimile Support for i. A mali…

Mitigation only
Fix from $1,950 2025-06-25
I HIGH 7.5
CVE-2025-33122

IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 could allow a user to gain elevated privileges due to an unqualified library call in IBM Advanced Job Scheduler for…

Mitigation only
Fix from $1,950 2025-06-17
I HIGH 8.5
CVE-2024-55898

IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user with the capability to compile or restore a program to gain elevated privileges due to an unqualified…

Mitigation only
Fix from $1,950 2025-02-24
Cognos Dashboards On Cloud Pak For Data HIGH 8.8
CVE-2024-41739

IBM Cognos Dashboards 4.0.7 and 5.0.0 on Cloud Pak for Data could allow a remote attacker to perform unauthorized actions due to dependency confusion.

Mitigation only
Fix from $1,950 2025-01-24
I HIGH 7.8
CVE-2024-38330

IBM System Management for i 7.2, 7.3, and 7.4 could allow a local user to gain elevated privileges due to an unqualified library program call. A mal…

Mitigation only
Fix from $1,950 2024-07-08
Rational Developer For I HIGH 7.8
CVE-2024-25050

IBM i 7.2, 7.3, 7.4, 7.5 and IBM Rational Development Studio for i 7.2, 7.3, 7.4, 7.5 networking and compiler infrastructure could allow a local user…

Mitigation only
Fix from $1,950 2024-04-28
I HIGH 7.8
CVE-2024-22346

Db2 for IBM i 7.2, 7.3, 7.4, and 7.5 infrastructure could allow a local user to gain elevated privileges due to an unqualified library call. A malici…

Patch available
Fix from $1,950 2024-03-14
Db2 MEDIUM 6.5
CVE-2023-27859

IBM Db2 10.1, 10.5, and 11.1 could allow a remote user to execute arbitrary code caused by installing like named jar files across multiple databases.…

Fix: after 11.5.9
Fix from $1,600 2024-01-22
I HIGH 7.8
CVE-2023-43064

Facsimile Support for IBM i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqualified library call. A malici…

Patch available
Fix from $1,950 2023-12-25
Storage Protect HIGH 7.8
CVE-2023-35897

IBM Spectrum Protect Client and IBM Storage Protect for Virtual Environments 8.1.0.0 through 8.1.19.0 could allow a local user to execute arbitrary c…

Fix: after 8.1.19.0
Fix from $1,950 2023-10-06
I Access Client Solutions MEDIUM 6.7
CVE-2022-40746

IBM i Access Family 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.0 could allow a local authenticated attacker to execute arbitrary code on the syste…

Fix: after 1.1.9.0
Fix from $1,600 2022-11-21
I2 Ibase MEDIUM 6.5
CVE-2020-4623

IBM i2 iBase 8.9.13 could allow a local authenticated attacker to execute arbitrary code on the system, caused by a DLL search order hijacking flaw. …

Patch available
Fix from $1,600 2021-07-26
Db2 HIGH 7.8
CVE-2019-4588

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to execute arbitrary code …

Mitigation only
Fix from $1,950 2021-05-26
Db2 High Performance Unload Load HIGH 7.8
CVE-2019-4447

IBM DB2 High Performance Unload load for LUW 6.1, 6.1.0.1, 6.1.0.1 IF1, 6.1.0.2, 6.1.0.2 IF1, and 6.1.0.1 IF2 db2hpum_debug is a setuid root binary w…

Patch available
Fix from $1,950 2019-08-26
Java HIGH 7.8
CVE-2019-4473

Multiple binaries in IBM SDK, Java Technology Edition 7, 7R, and 8 on the AIX platform use insecure absolute RPATHs, which may facilitate code inject…

Mitigation only
Fix from $1,950 2019-08-05
Db2 HIGH 7.8
CVE-2019-4094

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 binaries load shared libraries from an untrusted path pot…

Patch available
Fix from $1,950 2019-03-21
Sdk HIGH 7.8
CVE-2018-1890

IBM SDK, Java Technology Edition Version 8 on the AIX platform uses absolute RPATHs which may facilitate code injection and privilege elevation by lo…

Patch available
Fix from $1,950 2019-03-11