Vulnerabilities in IBM

5,658 results
Vexday analysis

Com 4.716 CVEs catalogadas, o portfólio da IBM acumula um volume expressivo de vulnerabilidades, embora sua taxa de exploração ativa — 5 entradas no catálogo KEV da CISA, representando 0,11% do total — esteja abaixo da média geral do catálogo (0,45%), o que sugere menor aproveitamento ativo em comparação proporcional com outros vendors. A atenção deve se concentrar em CVE-2022-47986, cuja pontuação EPSS de 0,9997 indica probabilidade extremamente elevada de exploração ativa, tornando-a prioridade imediata de mitigação. As 92 CVEs críticas e 18 com PoC pública ampliam a superfície de risco concreto, especialmente considerando que 129 novas vulnerabilidades surgiram nos últimos 90 dias, indicando ritmo relevante de descoberta recente. O tipo de falha mais recorrente, CWE-79 (Cross-Site Scripting), aponta para fragilidades persistentes na camada de apresentação que exigem atenção continuada em práticas de desenvolvimento e validação de entrada.

CVE-2026-87958HIGHIBM® Db2® is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditionsEPSS 0.4%CVE-2024-37071MEDIUMIBM Db2 denial of serviceEPSS 0.4%CVE-2026-18531MEDIUMIBM MAS uses axios-1.15.2, protobufjs-8.0.1 and undici-7.26 which is vulnerable to multiple CVEs, and contains vulnerabilities related to missing Secure attribute on mas-redirect-uri cookie and weak HMAC Session SecretEPSS 0.4%CVE-2026-84842HIGHIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.4%CVE-2021-20580MEDIUMIBM Planning Analytics 2.0 could be vulnerable to cross-site request forgery (CSRF) which could allow an attacker to execute malicious and uEPSS 0.4%CVE-2018-1448HIGHIBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) contains a vulnerability that could allow a locaEPSS 0.4%CVE-2017-1381—IBM WebSphere Application Server Proxy Server or On-demand-router (ODR) 7.0, 8.0, 8.5, 9.0 and could allow a local attacker to obtain sensitEPSS 0.4%CVE-2026-7528HIGHUnauthenticated File Upload Vulnerability Allows Disk Space Exhaustion and Path Disclosure in Langflow OSSEPSS 0.4%CVE-2026-17645CRITICALIBM Financial Transaction Manager (FTM) is Impacted by Multiple VulnerabilitiesEPSS 0.4%CVE-2026-78658MEDIUMIBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an information disclosure vulnerabilityEPSS 0.4%CVE-2018-1431HIGHA vulnerability in GSKit affects IBM Spectrum Scale 4.1.1, 4.2.0, 4.2.1, 4.2.3, and 5.0.0 that could allow a local attacker to obtain controEPSS 0.4%CVE-2026-19646CRITICALMultiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration AgentEPSS 0.4%CVE-2023-25928MEDIUMIBM InfoSphere Information Server cross-site scriptingEPSS 0.4%CVE-2026-11711MEDIUMIBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilitiesEPSS 0.4%CVE-2026-10534HIGHIBM® Db2® is vulnerable to buffer overflow in the IXF IMPORT parserEPSS 0.4%CVE-2024-22357MEDIUMIBM Sterling B2B Integrator cross-site scriptingEPSS 0.4%CVE-2017-1654MEDIUMIBM Spectrum Scale 4.1.1 and 4.2.0 - 4.2.3 could allow a local unprivileged user access to information located in dump files. User data coulEPSS 0.4%CVE-2026-17476MEDIUMIBM i Is Affected By Multiple Vulnerabilities in IBM Java SDK and IBM Java RuntimeEPSS 0.4%CVE-2018-1410—IBM Notes Diagnostics (IBM Client Application Access and IBM Notes) could allow a local user to execute commands on the system. By crafting EPSS 0.4%CVE-2024-49823MEDIUMIBM Common Cryptographic Architecture denial of serviceEPSS 0.4%