Overview / Research / Research, CVEs & coverage
Original IBM i research, advisories and press
The complete public record: vulnerability research, the CVEs we have reported, conference talks, and media coverage of our IBM i work.
Publications
Articles & conference talks
Deep technical write-ups and talks presented at conferences including REcon and TROOPERS.
2026.06.05Article
Unauthenticated RCE as QSECOFR via IBM i Management Central2025.10.22Article
IBM i LIBL Autopwn: Kill the Vulnerability Class2025.09.04Article
Exploit development for IBM i2025.01.21Article
Vulnerability Archeology: Stealing Passwords with IBM i Access Client Solutions2024.06.29Talk
Control Flow Integrity on IBM i▶2024.06.26Talk
IBM i for Wintel Hackers▶2023.08.22Article
Technical Details of CVE-2023-30988 - IBM Facsimile Support Privilege Escalation2023.07.03Article
Technical Details of CVE-2023-30990 - Unauthenticated RCE in IBM i DDM Service2023.03.30Article
Booby Trapping IBM i2023.01.20Article
Abusing Adopted Authority on IBM i2022.09.28Article
Another Tale of IBM i (AS/400) Hacking2022.09.05Article
Simple IBM i (AS/400) hacking
Advisories
Public IBM i vulnerabilities reported by Silent Signal
Each entry links to the official IBM advisory.
| CVE | IBM advisory description |
|---|---|
| CVE-2025-36004 | Privilege escalation via unqualified library call in IBM Facsimile Support for i |
| CVE-2025-33122 | Privilege escalation via unqualified library call in IBM Advanced Job Scheduler for i |
| CVE-2025-33108 | Privilege escalation via unqualified library call in Backup, Recovery and Media Services for i |
| CVE-2024-38330 | Privilege escalation via unqualified library calls in Managed System Services / System Management for i |
| CVE-2024-31870 | User profile enumeration via a supplied table function in Db2 for i |
| CVE-2024-31878 | SST user profile enumeration in IBM i Service Tools Server |
| CVE-2024-31879 | Denial of service via deserialization of untrusted data in Management Central |
| CVE-2023-40686 / CVE-2023-40685 | Local privilege escalation due to flaws in Management Central |
| CVE-2023-40378 | Local privilege escalation via a flaw in IBM Directory Server for i |
| CVE-2023-40377 | Local privilege escalation in IBM Backup, Recovery & Media Services for i |
| CVE-2023-40375 | Local privilege escalation in the Integrated application server for IBM i |
| CVE-2023-30990 | CL command execution via exploitation of DDM architecture |
| CVE-2023-30989 | Local privilege escalation in IBM Performance Tools for i |
| CVE-2023-30988 | Local privilege escalation in IBM Facsimile Support for i |
Coverage
News articles & videos
Independent coverage of our IBM i security research.
IT JungleNews
ACS Password Leaks Are A Security Issue On IBM iCyber Security NewsNews
Attackers Exploit IBM i Access Client Solutions on Windows 11 To Steal PasswordsProximityNews
Ethical hackers uncover misconfiguration vulnerabilities in the IBM i platformIT JungleNews
Ethical Hackers Discuss Penetration Work On IBM iIT JungleNews
2023: An IBM i Year in ReviewIT JungleNews
Spooky New Security Vulns Lurking on IBM iYahoo FinanceNews
Silent Signal Launches iCompliant to Provide Elevated Security for IBM i System UsersIT JungleNews
Midsummer Security Indicators: Hot and GloomyIT JungleNews
Serious New IBM i Vulns Exposed by Silent Signal — More On the WayIT JungleNews
New "High Priority" DDM Vulnerability Affects IBM iGlobeNewswireNews
Silent Signal Discovered a Critical Vulnerability in IBM i System — CVE-2023-30990IBM TVNews
IBM Technology UKI Brunch and Learn — What You Can Do With An IP AddressIT JungleNews
White Hats Completely Dismantle Menu-Based SecurityIT JungleNews
Pen Tester Silent Signal Targets IBM i
Get started
Put this research to work on your systems.
The same research behind these advisories drives every assessment, the iCompliant platform and the Exclusive Vulnerability Feed.
Talk to the research team →