Re: IBM Security Bulletins?

Jim Oberholtzer <midrangel-zbO79nAUJZvJTQUaaPvyeQC/[email protected]>
Newsgroups gmane.comp.hardware.ibm.midrange
Message-ID <[email protected]>
   See:

   There are multiple security vulnerabilities that has been identified in
   certain versions of IBM i Access Client Solutions (ACS). It is recommended
   to upgrade to the latest IBM i ACS available version, 1.1.9.14, to address
   these issues.

   The update includes fixes for the following vulnerabilities:

   All prior versions are vulnerable to:

     * Arbitrary code execution on Windows when installed for all users due
       to publicly writeable directory and configuration file.
     * Injection of rogue certificate authority due to publicly writeable
       truststore.
     * Zip slip path traversal exploit when importing a configuration.
     * Versions 1.1.8.3 through 1.1.9.13 are vulnerable to downloading
       unverified product code when configured to update from an IBM i.
     * The sample scripts in Documentation\Sample_Scripts\Linux_Mac_Other are
       vulnerable to arbitrary code execution via maliciously crafted input
       parameters.

     * [1]CVE-2026-13094
     * [2]CVE-2026-13105
     * [3]CVE-2026-13433
     * [4]CVE-2026-14866
     * [5]CVE-2026-14875
     * [6]CVE-2026-16695

    [7]Security Bulletin: IBM i Access Client Solutions (ACS) is Affected By
   Multiple Vulnerabilities

    

   Affected Products and Versions

   +------------------------------------------------+
   |Product                      |Versions          |
   |-----------------------------+------------------|
   |IBM i Access Client Solutions|1.1.8.3 - 1.1.9.13|
   +------------------------------------------------+

    

   Jim Oberholtzer
   Agile Technology Architects

     On Aug 12, 2026, at 12:29 PM, Shane Reeves via MIDRANGE-L
     <[email protected]> wrote:

     I didn't see the notice on ACS, can you point me to it?
     Shane Reeves
     date: Wed, 12 Aug 2026 08:45:05 -0500
     from: Jim Oberholtzer <[email protected]>
     subject: Re: IBM Security Bulletins?
     Yes.    Apparently there is a series of CVEs out that effect several
     products.  Mostly older code from my inspection but relevant to many
     locations.
     ACS needs the latest update as well.
     Jim Oberholtzer
     Agile Technology Architects
     --
     This is the Midrange Systems Technical Discussion (MIDRANGE-L) mailing
     list
     To post a message email: [email protected]
     To subscribe, unsubscribe, or change list options,
     visit: https://lists.midrange.com/mailman/listinfo/midrange-l
     or email: [email protected]
     Before posting, please take a moment to review the archives
     at https://archive.midrange.com/midrange-l.
     Please contact [email protected] for any subscription related
     questions.
     You can help support midrange.com by visiting
     https://donate.midrange.com and making a contribution.

References

   Visible links
   1. https://www.cve.org/CVERecord?id=CVE-2026-13094
	https://www.cve.org/CVERecord?id=CVE-2026-13094
   2. https://www.cve.org/CVERecord?id=CVE-2026-13105
	https://www.cve.org/CVERecord?id=CVE-2026-13105
   3. https://www.cve.org/CVERecord?id=CVE-2026-13433
	https://www.cve.org/CVERecord?id=CVE-2026-13433
   4. https://www.cve.org/CVERecord?id=CVE-2026-14866
	https://www.cve.org/CVERecord?id=CVE-2026-14866
   5. https://www.cve.org/CVERecord?id=CVE-2026-14875
	https://www.cve.org/CVERecord?id=CVE-2026-14875
   6. https://www.cve.org/CVERecord?id=CVE-2026-16695
	https://www.cve.org/CVERecord?id=CVE-2026-16695
   7. https://www.ibm.com/support/pages/node/7282954?
	https://www.ibm.com/support/pages/node/7282954?
-- 
This is the Midrange Systems Technical Discussion (MIDRANGE-L) mailing list
To post a message email: [email protected]
To subscribe, unsubscribe, or change list options,
visit: https://lists.midrange.com/mailman/listinfo/midrange-l
or email: [email protected]
Before posting, please take a moment to review the archives
at https://archive.midrange.com/midrange-l.

Please contact [email protected] for any subscription related questions.

You can help support midrange.com by visiting https://donate.midrange.com and making a contribution.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.