IBM i 7.6、7.5、7.4 和 7.3 版本允许经过身份验证的远程攻击者在“Navigator for i”中向文件系统放置文件,而这些文件本应被 Navigator 配置所阻止。这使得攻击者能够将文件上传到系统中 Navigator 支持原本未预期的位置,但前提是相应的用户配置文件本身已具备这种权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-16338 | 9.9 CRITICAL | DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
| CVE-2026-16673 | 8.8 HIGH | DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
| CVE-2026-16466 | 8.8 HIGH | DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
| CVE-2026-16428 | 8.8 HIGH | DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
| CVE-2026-17467 | 8.2 HIGH | Vulnerabilities exists in IBM Cloud Pak for Data System |
| CVE-2026-16335 | 8.1 HIGH | DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
| CVE-2026-17416 | 7.8 HIGH | IBM App Connect Enterprise Toolkit is vulnerable to arbitrary code execution due to multip |
| CVE-2026-17156 | 7.8 HIGH | IBM App Connect Enterprise Toolkit is vulnerable to arbitrary code execution due to multip |
| CVE-2026-17133 | 7.8 HIGH | IBM App Connect Enterprise Toolkit is vulnerable to arbitrary code execution due to multip |
| CVE-2026-16432 | 7.7 HIGH | DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
| CVE-2026-15955 | 7.5 HIGH | IBM® Data Server driver for JDBC and SQLJ could allow a remote attacker to perform an arbi |
| CVE-2026-13107 | 7.1 HIGH | Multiple secuirty vulnerabilies addressed with IBM Business Automation Workflow August 202 |
| CVE-2026-53708 | 6.6 MEDIUM | ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/te |
| CVE-2026-16187 | 6.5 MEDIUM | IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple v |
| CVE-2026-12767 | 6.5 MEDIUM | Langflow is vulnerable to server-side request forgery due to missing egress validation on |
| CVE-2026-17463 | 6.5 MEDIUM | IBM® Db2® could allow a remote authenticated attacker to cause a denial of service due to |
| CVE-2026-16702 | 6.5 MEDIUM | IBM® Db2® federated server could allow a remote authenticated attacker to cause a denial o |
| CVE-2026-15396 | 6.5 MEDIUM | IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple v |
| CVE-2026-15412 | 6.5 MEDIUM | IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple v |
| CVE-2026-15634 | 6.5 MEDIUM | IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple v |
Showing top 20 of 39 CVEs. View all on vendor page → →
No comments yet