As/400 systems security vulnerabilities

uticus1 pts0 comments

Iseries As 400 CVEs and Security Vulnerabilities - OpenCVE

MAIN NAVIGATION

Vulnerabilities

Vendors & Products

Weaknesses

Statistics

Search

Search

Toggle Dropdown

Query Builder

Save Query

Load Query

Use the Query Builder to create your own search query, or check out the documentation to learn the search syntax.

Search Examples

CVEs in KEV<br>CVEs with EPSS >= 80%<br>Crit. Microsoft<br>High Apache<br>SQL Injection (CWE-89)<br>Linux Kernel<br>High (CVSS 3.1)<br>Apache Struts<br>RCE (Remote Code Execution)<br>XSS (CWE-79)<br>Critical (CVSS 4.0)<br>CVEs to check

Search Results (3 CVEs found)

Export CSV

CVE<br>Vendors<br>Products<br>Updated<br>CVSS v3.1

CVE-2005-1238<br>1 Ibm<br>1 Iseries As 400<br>2026-04-16

N/A

By design, the built-in FTP server for iSeries AS/400 systems does not support a restricted document root, which allows attackers to read or write arbitrary files, including sensitive QSYS databases, via a full pathname in a GET or PUT request.

CVE-2005-1133<br>1 Ibm<br>1 Iseries As 400<br>2026-04-16

N/A

The POP3 server in IBM iSeries AS/400 returns different error messages when the user exists or not, which allows remote attackers to determine valid user IDs on the server.

CVE-2005-1025<br>1 Ibm<br>1 Iseries As 400<br>2026-04-16

N/A

The FTP server in AS/400 4.3, when running in IFS mode, allows remote attackers to obtain sensitive information via a symlink attack using RCMD and the ADDLNK utility, as demonstrated using the QSYS.LIB library.

Page 1 of 1.

Advanced Search Builder

&times;

Query will appear here as you build it...

CVE ID

Description

Title

Project

User Tag

Date Filter

Created<br>Updated

=" selected>>=

CVSS Score

CVSS v4.0<br>CVSS v3.1<br>CVSS v3.0<br>CVSS v2.0

=" selected>>=

KEV

Include CVEs in KEV catalog

EPSS Score

=" selected>>=

">>

CWE

Vendor

Product

Reset Builder<br>Close<br>Apply Query

cvss search query iseries cves builder

Related Articles