Vulnerabilities in IBM

5,658 results
Vexday analysis

Com 4.716 CVEs catalogadas, o portfólio da IBM acumula um volume expressivo de vulnerabilidades, embora sua taxa de exploração ativa — 5 entradas no catálogo KEV da CISA, representando 0,11% do total — esteja abaixo da média geral do catálogo (0,45%), o que sugere menor aproveitamento ativo em comparação proporcional com outros vendors. A atenção deve se concentrar em CVE-2022-47986, cuja pontuação EPSS de 0,9997 indica probabilidade extremamente elevada de exploração ativa, tornando-a prioridade imediata de mitigação. As 92 CVEs críticas e 18 com PoC pública ampliam a superfície de risco concreto, especialmente considerando que 129 novas vulnerabilidades surgiram nos últimos 90 dias, indicando ritmo relevante de descoberta recente. O tipo de falha mais recorrente, CWE-79 (Cross-Site Scripting), aponta para fragilidades persistentes na camada de apresentação que exigem atenção continuada em práticas de desenvolvimento e validação de entrada.

CVE-2022-22318MEDIUMIBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impeEPSS 0.4%CVE-2018-1487HIGHIBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5 and 11.1 binaries load shared libraries from an untrusted EPSS 0.4%CVE-2018-1635HIGHStack-based buffer overflow in oninit in IBM Informix Dynamic Server Enterprise Edition 12.1 allows an authenticated user to execute predefiEPSS 0.4%CVE-2025-36442MEDIUMIBM Db2 Denial of ServiceEPSS 0.4%CVE-2018-1636HIGHStack-based buffer overflow in oninit in IBM Informix Dynamic Server Enterprise Edition 12.1 allows an authenticated user to execute predefiEPSS 0.4%CVE-2025-14754HIGHIBM Cloud Pak for Data is vulnerable to OS command injectionEPSS 0.4%CVE-2026-17071LOWIBM i is Affected By Multiple Vulnerabilities in Digital Certificate ManagerEPSS 0.4%CVE-2026-81539HIGHDataStage on Cloud Pak for Data has several vulnerabilitiesEPSS 0.4%CVE-2024-35151MEDIUMIBM OpenPages information disclosureEPSS 0.4%CVE-2019-4038HIGHIBM Security Identity Manager 6.0 and 7.0 could allow an attacker to create unexpected control flow paths through the application, potentialEPSS 0.4%CVE-2026-7787HIGHUnauthenticated Session History Access via Public Flow ExecutionEPSS 0.4%CVE-2024-45072MEDIUMIBM WebSphere Application Server XML external entity injectionEPSS 0.4%CVE-2026-16827MEDIUMVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.4%CVE-2020-4983HIGHIBM Spectrum LSF 10.1 and IBM Spectrum LSF Suite 10.2 could allow a user on the local network who has privileges to submit LSF jobs to execuEPSS 0.4%CVE-2026-9077HIGHReliance on Untrusted Inputs in a Security Decision vulnerabilities in Model Context Protocol featuresEPSS 0.4%CVE-2026-17075MEDIUMIBM i is Affected By Multiple Vulnerabilities in Digital Certificate ManagerEPSS 0.4%CVE-2024-45086MEDIUMIBM WebSphere Application Server XML external entity injectionEPSS 0.4%CVE-2022-22313MEDIUMIBM QRadar Data Synchronization App information disclosureEPSS 0.4%CVE-2018-1874MEDIUMIBM API Connect 5.0.0.0 through 5.0.8.5 could display highly sensitive information to an attacker with physical access to the system. IBM X-EPSS 0.4%CVE-2024-22334MEDIUMIBM UrbanCode Deploy improper privilege controlEPSS 0.4%