Re: IBM Security Bulletins?
Jim Oberholtzer <midrangel-zbO79nAUJZvJTQUaaPvyeQC/[email protected]>
| Newsgroups | gmane.comp.hardware.ibm.midrange |
|---|---|
| Message-ID | <[email protected]> |
See:
There are multiple security vulnerabilities that has been identified in
certain versions of IBM i Access Client Solutions (ACS). It is recommended
to upgrade to the latest IBM i ACS available version, 1.1.9.14, to address
these issues.
The update includes fixes for the following vulnerabilities:
All prior versions are vulnerable to:
* Arbitrary code execution on Windows when installed for all users due
to publicly writeable directory and configuration file.
* Injection of rogue certificate authority due to publicly writeable
truststore.
* Zip slip path traversal exploit when importing a configuration.
* Versions 1.1.8.3 through 1.1.9.13 are vulnerable to downloading
unverified product code when configured to update from an IBM i.
* The sample scripts in Documentation\Sample_Scripts\Linux_Mac_Other are
vulnerable to arbitrary code execution via maliciously crafted input
parameters.
* [1]CVE-2026-13094
* [2]CVE-2026-13105
* [3]CVE-2026-13433
* [4]CVE-2026-14866
* [5]CVE-2026-14875
* [6]CVE-2026-16695
[7]Security Bulletin: IBM i Access Client Solutions (ACS) is Affected By
Multiple Vulnerabilities
Affected Products and Versions
+------------------------------------------------+
|Product |Versions |
|-----------------------------+------------------|
|IBM i Access Client Solutions|1.1.8.3 - 1.1.9.13|
+------------------------------------------------+
Jim Oberholtzer
Agile Technology Architects
On Aug 12, 2026, at 12:29 PM, Shane Reeves via MIDRANGE-L
<[email protected]> wrote:
I didn't see the notice on ACS, can you point me to it?
Shane Reeves
date: Wed, 12 Aug 2026 08:45:05 -0500
from: Jim Oberholtzer <[email protected]>
subject: Re: IBM Security Bulletins?
Yes. Apparently there is a series of CVEs out that effect several
products. Mostly older code from my inspection but relevant to many
locations.
ACS needs the latest update as well.
Jim Oberholtzer
Agile Technology Architects
--
This is the Midrange Systems Technical Discussion (MIDRANGE-L) mailing
list
To post a message email: [email protected]
To subscribe, unsubscribe, or change list options,
visit: https://lists.midrange.com/mailman/listinfo/midrange-l
or email: [email protected]
Before posting, please take a moment to review the archives
at https://archive.midrange.com/midrange-l.
Please contact [email protected] for any subscription related
questions.
You can help support midrange.com by visiting
https://donate.midrange.com and making a contribution.
References
Visible links
1. https://www.cve.org/CVERecord?id=CVE-2026-13094
https://www.cve.org/CVERecord?id=CVE-2026-13094
2. https://www.cve.org/CVERecord?id=CVE-2026-13105
https://www.cve.org/CVERecord?id=CVE-2026-13105
3. https://www.cve.org/CVERecord?id=CVE-2026-13433
https://www.cve.org/CVERecord?id=CVE-2026-13433
4. https://www.cve.org/CVERecord?id=CVE-2026-14866
https://www.cve.org/CVERecord?id=CVE-2026-14866
5. https://www.cve.org/CVERecord?id=CVE-2026-14875
https://www.cve.org/CVERecord?id=CVE-2026-14875
6. https://www.cve.org/CVERecord?id=CVE-2026-16695
https://www.cve.org/CVERecord?id=CVE-2026-16695
7. https://www.ibm.com/support/pages/node/7282954?
https://www.ibm.com/support/pages/node/7282954?
--
This is the Midrange Systems Technical Discussion (MIDRANGE-L) mailing list
To post a message email: [email protected]
To subscribe, unsubscribe, or change list options,
visit: https://lists.midrange.com/mailman/listinfo/midrange-l
or email: [email protected]
Before posting, please take a moment to review the archives
at https://archive.midrange.com/midrange-l.
Please contact [email protected] for any subscription related questions.
You can help support midrange.com by visiting https://donate.midrange.com and making a contribution.