Vulnerabilities in IBM

5,658 results
Vexday analysis

Com 4.716 CVEs catalogadas, o portfólio da IBM acumula um volume expressivo de vulnerabilidades, embora sua taxa de exploração ativa — 5 entradas no catálogo KEV da CISA, representando 0,11% do total — esteja abaixo da média geral do catálogo (0,45%), o que sugere menor aproveitamento ativo em comparação proporcional com outros vendors. A atenção deve se concentrar em CVE-2022-47986, cuja pontuação EPSS de 0,9997 indica probabilidade extremamente elevada de exploração ativa, tornando-a prioridade imediata de mitigação. As 92 CVEs críticas e 18 com PoC pública ampliam a superfície de risco concreto, especialmente considerando que 129 novas vulnerabilidades surgiram nos últimos 90 dias, indicando ritmo relevante de descoberta recente. O tipo de falha mais recorrente, CWE-79 (Cross-Site Scripting), aponta para fragilidades persistentes na camada de apresentação que exigem atenção continuada em práticas de desenvolvimento e validação de entrada.

CVE-2023-45187MEDIUMIBM Engineering Lifecycle Optimization - Publishing session fixationEPSS 0.4%CVE-2018-1768MEDIUMIBM Spectrum Protect Plus 10.1.0 and 10.1.1 could disclose sensitive information when an authorized user executes a test operation, the userEPSS 0.4%CVE-2023-32344MEDIUMIBM Cognos Analytics cross-site request forgeryEPSS 0.4%CVE-2026-18670HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.4%CVE-2026-12355HIGHIBM MQ Resource Adapter IVT servlet is vulnerable to unauthenticated remote code executionEPSS 0.4%CVE-2026-17057MEDIUMIBM i is Affected By Denial of Service Vulnerabilities in NFS [, ]EPSS 0.4%CVE-2019-4686LOWIBM Security Guardium Data Encryption (GDE) 3.0.0.2 does not set the secure attribute on authorization tokens or session cookies. Attackers EPSS 0.4%CVE-2020-4230MEDIUMIBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 and 11.5 is vulnerable to an escalation of privilege when an authentiEPSS 0.4%CVE-2018-1841MEDIUMIBM Cloud Private 2.1.0 could allow a local user to obtain the CA Private Key due to it being world readable in boot/master node. IBM X-ForcEPSS 0.4%CVE-2017-1439—IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user with DB2 instance ownerEPSS 0.4%CVE-2017-1438—IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user with DB2 instance ownerEPSS 0.4%CVE-2026-12085MEDIUMIBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptable to an Insertion of Sensitive Information Into Sent Data vulnerabilityEPSS 0.4%CVE-2023-33849LOWIBM CICS TX information disclosureEPSS 0.4%CVE-2024-45653MEDIUMIBM Sterling Connect:Direct Web Services information disclosureEPSS 0.4%CVE-2018-1664MEDIUMIBM DataPower Gateway 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0 - 7.5.1.15, 7.5.2.0 - 7.5.2.15, and 7.6.0.0 - 7.6.EPSS 0.4%CVE-2017-1756MEDIUMIBM Business Process Manager 8.6 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 1358EPSS 0.4%CVE-2026-10128MEDIUMLangflow is affected by weaknesses in secret handling and sensitive configuration accessEPSS 0.4%CVE-2023-38020MEDIUMIBM SOAR QRadar Plugin App log injectionEPSS 0.4%CVE-2026-8405MEDIUMIBM Guardium Data Protection is affected by Exposure of Sensitive Information vulnerabilityEPSS 0.4%CVE-2022-32759MEDIUMIBM Security Directory Server information disclosureEPSS 0.4%