Vulnerabilities in IBM

5,595 results
Vexday analysis

Com 4.716 CVEs catalogadas, o portfólio da IBM acumula um volume expressivo de vulnerabilidades, embora sua taxa de exploração ativa — 5 entradas no catálogo KEV da CISA, representando 0,11% do total — esteja abaixo da média geral do catálogo (0,45%), o que sugere menor aproveitamento ativo em comparação proporcional com outros vendors. A atenção deve se concentrar em CVE-2022-47986, cuja pontuação EPSS de 0,9997 indica probabilidade extremamente elevada de exploração ativa, tornando-a prioridade imediata de mitigação. As 92 CVEs críticas e 18 com PoC pública ampliam a superfície de risco concreto, especialmente considerando que 129 novas vulnerabilidades surgiram nos últimos 90 dias, indicando ritmo relevante de descoberta recente. O tipo de falha mais recorrente, CWE-79 (Cross-Site Scripting), aponta para fragilidades persistentes na camada de apresentação que exigem atenção continuada em práticas de desenvolvimento e validação de entrada.

CVE-2018-1663MEDIUMIBM DataPower Gateways 7.5, 7.5.1, 7.5.2, 7.6, and 2018.4 could allow a remote attacker to obtain sensitive information, caused by the failuEPSS 2.3%CVE-2018-1990MEDIUMIBM Cloud App Management V2018.2.0, V2018.4.0, and V2018.4.1 could allow an attacker to obtain sensitive configuration information using a sEPSS 2.3%CVE-2017-1253IBM Security Guardium 10.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-cEPSS 2.3%CVE-2021-29695MEDIUMIBM Host firmware for LC-class Systems could allow a remote attacker to traverse directories on the system. An attacker could send a specialEPSS 2.3%CVE-2019-4008CRITICALAPI Connect V2018.1 through 2018.4.1.1 is impacted by access token leak. Authorization tokens in some URLs can result in the tokens being wrEPSS 2.3%CVE-2017-1235IBM WebSphere MQ 8.0 could allow an authenticated user to cause a premature termination of a client application thread which could potentialEPSS 2.3%CVE-2017-1476MEDIUMIBM Security Access Manager Appliance 7.0.0, 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 could allow a remote attacker to obtain sensitEPSS 2.3%CVE-2020-5016MEDIUMIBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. When applicatioEPSS 2.3%CVE-2019-4210CRITICALIBM QRadar SIEM 7.3.2 could allow a user to bypass authentication exposing certain functionality which could lead to information disclosure EPSS 2.2%CVE-2018-1437HIGHIBM Notes 8.5 and 9.0 could allow an attacker to execute arbitrary code on the system, caused by an error related to multiple untrusted searEPSS 2.2%CVE-2018-1695HIGHIBM WebSphere Application Server 7.0, 8.0, and 8.5.5 installations using Form Login could allow a remote attacker to conduct spoofing attackEPSS 2.2%CVE-2018-1850HIGHIBM Security Access Manager Appliance 9.0.3.1, 9.0.4.0 and 9.0.5.0 could allow unauthorized administration operations when Advanced Access CEPSS 2.2%CVE-2017-1499IBM Maximo Asset Management 7.5 and 7.6 could allow a remote attacker to include arbitrary files, which could allow the attacker to execute EPSS 2.2%CVE-2020-4579HIGHIBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sending a specially craftEPSS 2.2%CVE-2016-8964IBM BigFix Inventory v9 9.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentialsEPSS 2.2%CVE-2020-4494HIGHIBM Spectrum Protect Client 8.1.7.0 through 8.1.9.1 (Linux and Windows), 8.1.9.0 trough 8.1.9.1 (AIX) and IBM Spectrum Protect for Space ManEPSS 2.2%CVE-2019-4520HIGHIBM Security Directory Server 6.4.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account creEPSS 2.2%CVE-2022-22394HIGHThe IBM Spectrum Protect 8.1.14.000 server could allow a remote attacker to bypass security restrictions, caused by improper enforcement of EPSS 2.2%CVE-2018-1475IBM BigFix Platform 9.2 and 9.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentEPSS 2.2%CVE-2019-4310HIGHIBM Security Guardium Big Data Intelligence 4.0 (SonarG) uses an inadequate account lockout setting that could allow a remote attacker to brEPSS 2.2%