IBM i 平台的“IBM 管理运行时专家”(IBM Application Runtime Expert for i, 版本 1R1M0)可能存在一个安全漏洞,允许远程攻击者提升权限。该漏洞的成因是 ARE(Application Runtime Expert)GUI 组件在处理用户请求时存在逻辑缺陷。 具体而言,未认证的攻击者可以利用此漏洞,在其他已认证用户的配置文件下执行操作,从而在 IBM i 系统上获得提升后的权限。 关键要点总结: 受影响组件:IBM i 的 ARE(Application Runtim
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| IBM | Administration Runtime Expert for i | 1R1M0 |
cpe:2.3:a:ibm:administration_runtime_expert_for_i:1r1m0:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-19295 | 9.9 CRITICAL | Langflow is affected by multiple remote code execution vulnerabilities due to insufficient |
| CVE-2026-19286 | 9.8 CRITICAL | Langflow is affected by multiple remote code execution vulnerabilities due to insufficient |
| CVE-2026-3627 | 9.1 CRITICAL | Multiple Vulnerabilities in IBM Concert Software |
| CVE-2026-18729 | 8.8 HIGH | Langflow is affected by multiple remote code execution vulnerabilities due to insufficient |
| CVE-2026-18904 | 8.2 HIGH | Langflow is affected by multiple authentication bypass, path traversal, authorization, and |
| CVE-2026-18891 | 8.2 HIGH | Langflow is affected by multiple authentication bypass, path traversal, authorization, and |
| CVE-2026-18899 | 7.5 HIGH | Langflow is affected by multiple authentication bypass, path traversal, authorization, and |
| CVE-2026-17203 | 7.5 HIGH | IBM Application Runtime Expert (ARE) for IBM i is vulnerable to a user gaining elevated pr |
| CVE-2026-16821 | 7.0 HIGH | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-19294 | 6.4 MEDIUM | Langflow is affected by multiple authentication bypass, path traversal, authorization, and |
| CVE-2026-3686 | 6.2 MEDIUM | Vulnerabilities exists in IBM Cloud Pak for Data System |
| CVE-2025-64649 | 5.9 MEDIUM | Multiple Vulnerabilities in IBM Concert Software |
| CVE-2025-36290 | 5.9 MEDIUM | IBM Integrated Analytics System (IIAS) is affected by improper SSL/TLS certificate validat |
| CVE-2025-36271 | 5.9 MEDIUM | IBM Integrated Analytics System (IIAS) is affected by a predictable salt vulnerability in |
| CVE-2026-18545 | 4.3 MEDIUM | Langflow is affected by multiple authentication bypass, path traversal, authorization, and |
No comments yet