Vulnerabilities in IBM

5,658 results
Vexday analysis

Com 4.716 CVEs catalogadas, o portfólio da IBM acumula um volume expressivo de vulnerabilidades, embora sua taxa de exploração ativa — 5 entradas no catálogo KEV da CISA, representando 0,11% do total — esteja abaixo da média geral do catálogo (0,45%), o que sugere menor aproveitamento ativo em comparação proporcional com outros vendors. A atenção deve se concentrar em CVE-2022-47986, cuja pontuação EPSS de 0,9997 indica probabilidade extremamente elevada de exploração ativa, tornando-a prioridade imediata de mitigação. As 92 CVEs críticas e 18 com PoC pública ampliam a superfície de risco concreto, especialmente considerando que 129 novas vulnerabilidades surgiram nos últimos 90 dias, indicando ritmo relevante de descoberta recente. O tipo de falha mais recorrente, CWE-79 (Cross-Site Scripting), aponta para fragilidades persistentes na camada de apresentação que exigem atenção continuada em práticas de desenvolvimento e validação de entrada.

CVE-2022-22488MEDIUMIBM OpenBMC denial of serviceEPSS 0.5%CVE-2026-9074CRITICALIBM API Connect SQL InjectionEPSS 0.5%CVE-2021-38915MEDIUMIBM Data Risk Manager 2.0.6 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 209947.EPSS 0.5%CVE-2021-39035MEDIUMIBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 is vulnerable to EPSS 0.5%CVE-2023-46169MEDIUMIBM DS8900F file manipulationEPSS 0.5%CVE-2022-35281MEDIUMIBM Maximo Application Suite command injectionEPSS 0.5%CVE-2026-80424CRITICALDataStage on Cloud Pak for Data has several vulnerabilities due to open source softwareEPSS 0.5%CVE-2021-20345MEDIUMIBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacEPSS 0.5%CVE-2021-20451MEDIUMIBM Cognos Controller SQL injectionEPSS 0.5%CVE-2024-51453MEDIUMIBM Sterling Secure Proxy directory traversalEPSS 0.5%CVE-2021-20544MEDIUMIBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticaEPSS 0.5%CVE-2021-20343MEDIUMIBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacEPSS 0.5%CVE-2021-20421MEDIUMIBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticaEPSS 0.5%CVE-2021-39020LOWIBM Guardium Data Encryption (GDE) 4.0.0.7 and lower stores sensitive information in URL parameters. This may lead to information disclosureEPSS 0.5%CVE-2021-29863MEDIUMIBM QRadar SIEM 7.3 and 7.4 is vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorizEPSS 0.5%CVE-2021-20347MEDIUMIBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacEPSS 0.5%CVE-2021-20348MEDIUMIBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacEPSS 0.5%CVE-2021-20346MEDIUMIBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacEPSS 0.5%CVE-2023-28958HIGHIBM Watson Knowledge Catalog CSV injectionEPSS 0.5%CVE-2026-16856HIGHIBM i is Affected By Multiple Vulnerabilities in Domain Name SystemEPSS 0.5%