Vulnerabilities in IBM

5,658 results
Vexday analysis

Com 4.716 CVEs catalogadas, o portfólio da IBM acumula um volume expressivo de vulnerabilidades, embora sua taxa de exploração ativa — 5 entradas no catálogo KEV da CISA, representando 0,11% do total — esteja abaixo da média geral do catálogo (0,45%), o que sugere menor aproveitamento ativo em comparação proporcional com outros vendors. A atenção deve se concentrar em CVE-2022-47986, cuja pontuação EPSS de 0,9997 indica probabilidade extremamente elevada de exploração ativa, tornando-a prioridade imediata de mitigação. As 92 CVEs críticas e 18 com PoC pública ampliam a superfície de risco concreto, especialmente considerando que 129 novas vulnerabilidades surgiram nos últimos 90 dias, indicando ritmo relevante de descoberta recente. O tipo de falha mais recorrente, CWE-79 (Cross-Site Scripting), aponta para fragilidades persistentes na camada de apresentação que exigem atenção continuada em práticas de desenvolvimento e validação de entrada.

CVE-2018-1998HIGHIBM WebSphere MQ 8.0.0.0 through 9.1.1 could allow a local user to inject code that could be executed with root privileges. This is due to aEPSS 0.4%CVE-2023-24966MEDIUMIBM WebSphere Application Server cross-site scriptingEPSS 0.4%CVE-2024-49350MEDIUMIBM Db2 denial of serviceEPSS 0.4%CVE-2026-11546HIGHIBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerabilityEPSS 0.4%CVE-2025-33090HIGHIBM Concert Software denial of serviceEPSS 0.4%CVE-2020-4265HIGHIBM i2 Intelligent Analyis Platform 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruptioEPSS 0.4%CVE-2026-1918MEDIUMIBM Sterling B2B Integrator and IBM Sterling File Gateway store sensitive information in a log fileEPSS 0.4%CVE-2023-25924MEDIUMIBM Security Key Lifecycle Manager improper authorizationEPSS 0.4%CVE-2020-4826MEDIUMIBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to cross-site request forgery which could allow aEPSS 0.4%CVE-2020-4497MEDIUMIBM Spectrum Protect Plus information disclosureEPSS 0.4%CVE-2025-36070MEDIUMIBM Db2 Denial of ServiceEPSS 0.4%CVE-2020-4827MEDIUMIBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to cross-site request forgery which could allow aEPSS 0.4%CVE-2018-1565HIGHIBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to overflow a buffer whEPSS 0.4%CVE-2020-4938MEDIUMIBM MQ Appliance 9.1 and 9.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorizedEPSS 0.4%CVE-2021-29837MEDIUMIBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attackEPSS 0.4%CVE-2022-36776MEDIUMIBM Cloud Pak for Security (CP4S) 1.10.0.0 79and 1.10.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arEPSS 0.4%CVE-2021-20489MEDIUMIBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicEPSS 0.4%CVE-2021-29757MEDIUMIBM QRadar User Behavior Analytics 4.1.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and EPSS 0.4%CVE-2018-1544HIGHIBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to overflow a buffer whEPSS 0.4%CVE-2018-1443MEDIUMAn XML parsing vulnerability affects IBM SAML-based single sign-on (SSO) systems (IBM Security Access Manager 9.0.0 - 9.0.4 and IBM Tivoli FEPSS 0.4%