IBM i Security Alert: OpenSSH (02/26/2024)

Hello everyone, today another OpenSSH security bulletin.OpenSSH is the first connectivity tool for remote connection using the SSH protocol. It uses traffic encryption to eliminate eavesdropping, connection hijacking and other attacks. As a result of this new vulnerability, OpenSSH is vulnerable to a machine-in-the-middle attack caused by a flaw in the protocol’s extension negotiation process.…

Read More

IBM i security alert: IBM HTTP server (20/02/2024)

Today’s security bulletin concerns the IBM HTTP server (powered by Apache), vulnerable to 2 major flaws that could cause malicious file downloads (CVE-2023-45802) and/or data theft (CVE-2023-31122). Firstly, arbitrary files can be downloaded via the stream management platform: Apache StreamPark. Within this development framework, an authenticated attacker could download these files by sending 2 HTTP…

Read More

IBM i Security Alert: IBM Rational Developer for i (02/14/2024)

IBM Rational Developer for I allows you to create, manage and modernize applications on the IBM i platform.It integrates development tools such as search, modify, create, analyze and restructure capabilities.The IDE (integrated development environment) also contains several debuggers for the Eclipse framework, widely used to simplify and accelerate application development and modernization. One of the…

Read More

IBM i Security Alert: IBM i Access Client Solutions with NTLM (08/02/2024)

Hello everyone, new security bulletin concerning IBM i Access Client Solutions (ACS).The platform/independent interface is vulnerable to the theft of remote credentials when NTLM is enabled on Windows workstations. NTLM (New Technology LAN Manager) is a suite of Microsoft security protocols designed to ensure user authentication, integrity and confidentiality. It is also the successor to…

Read More

IBM i Security Alert: Oracle Java SE, JSEE, CORBA (07/02/2024)

Three new vulnerabilities discovered in IBM® SDK Java™ Technology Edition and IBM® Runtime Environment Java™ used by IBM i. These flaws can cause a denial of service and/or have a significant impact on its integrity (CVE-2023-22081 and CVE-2023-22067). Oracle Java SE (Oracle GraalVM) contains an unspecified vulnerability. The CVSS risk score is 5.3 for the…

Read More

IBM i Security Alert: 3 critical vulnerabilities in IBM i Access Client Solutions! (12/12/2023)

📅 New security bulletin – December IBM i Access Client Solutions (ACS) has been hit by three major vulnerabilities, including one enabling remote code execution 🖥️⚠️ and others jeopardizing password security 🔑. 🚨 Summary of identified faults 🔎 IBM i Access Client Solutions is vulnerable to :✔️ Remote code execution via a serialized object authentication…

Read More

IBM i Security Alert: Samba server (13/11/2023)

New security alert of very high severity (CVSS Base score 8.8), concerning the Samba server.A flaw in its system could enable an attacker to bypass the security restrictions (CVE-2023-4091) and (CVE-2023-4091). Samba is a server that uses TCP/IP on IBM i to interact with Microsoft® Windows® clients or servers as if it were a Windows…

Read More

IBM i Security Alert: Management Central (07/11/2023)

New vulnerability detected in IBM’s security bulletin at the end of October (CVE-2023-40685, CVE-2023-40686).IBM i is vulnerable to local privilege escalation due to flaws in “Management Central”, and these vulnerabilities exist even when the centralized management software is not being used for system management tasks. A malicious actor with command-line access to the operating system…

Read More