Iseries As 400 CVEs and Security Vulnerabilities - OpenCVE
MAIN NAVIGATION
Vulnerabilities
Vendors & Products
Weaknesses
Statistics
Search
Search
Toggle Dropdown
Query Builder
Save Query
Load Query
Use the Query Builder to create your own search query, or check out the documentation to learn the search syntax.
Search Examples
CVEs in KEV<br>CVEs with EPSS >= 80%<br>Crit. Microsoft<br>High Apache<br>SQL Injection (CWE-89)<br>Linux Kernel<br>High (CVSS 3.1)<br>Apache Struts<br>RCE (Remote Code Execution)<br>XSS (CWE-79)<br>Critical (CVSS 4.0)<br>CVEs to check
Search Results (3 CVEs found)
Export CSV
CVE<br>Vendors<br>Products<br>Updated<br>CVSS v3.1
CVE-2005-1238<br>1 Ibm<br>1 Iseries As 400<br>2026-04-16
N/A
By design, the built-in FTP server for iSeries AS/400 systems does not support a restricted document root, which allows attackers to read or write arbitrary files, including sensitive QSYS databases, via a full pathname in a GET or PUT request.
CVE-2005-1133<br>1 Ibm<br>1 Iseries As 400<br>2026-04-16
N/A
The POP3 server in IBM iSeries AS/400 returns different error messages when the user exists or not, which allows remote attackers to determine valid user IDs on the server.
CVE-2005-1025<br>1 Ibm<br>1 Iseries As 400<br>2026-04-16
N/A
The FTP server in AS/400 4.3, when running in IFS mode, allows remote attackers to obtain sensitive information via a symlink attack using RCMD and the ADDLNK utility, as demonstrated using the QSYS.LIB library.
Page 1 of 1.
Advanced Search Builder
×
Query will appear here as you build it...
CVE ID
Description
Title
Project
User Tag
Date Filter
Created<br>Updated
=" selected>>=
CVSS Score
CVSS v4.0<br>CVSS v3.1<br>CVSS v3.0<br>CVSS v2.0
=" selected>>=
KEV
Include CVEs in KEV catalog
EPSS Score
=" selected>>=
">>
CWE
Vendor
Product
Reset Builder<br>Close<br>Apply Query