Vulnerabilities in IBM

5,658 results
Vexday analysis

Com 4.716 CVEs catalogadas, o portfólio da IBM acumula um volume expressivo de vulnerabilidades, embora sua taxa de exploração ativa — 5 entradas no catálogo KEV da CISA, representando 0,11% do total — esteja abaixo da média geral do catálogo (0,45%), o que sugere menor aproveitamento ativo em comparação proporcional com outros vendors. A atenção deve se concentrar em CVE-2022-47986, cuja pontuação EPSS de 0,9997 indica probabilidade extremamente elevada de exploração ativa, tornando-a prioridade imediata de mitigação. As 92 CVEs críticas e 18 com PoC pública ampliam a superfície de risco concreto, especialmente considerando que 129 novas vulnerabilidades surgiram nos últimos 90 dias, indicando ritmo relevante de descoberta recente. O tipo de falha mais recorrente, CWE-79 (Cross-Site Scripting), aponta para fragilidades persistentes na camada de apresentação que exigem atenção continuada em práticas de desenvolvimento e validação de entrada.

CVE-2024-37532HIGHIBM WebSphere Application Server identity spoofingEPSS 0.4%CVE-2022-41299MEDIUMIBM Cloud Transformation Advisor cross-site scriptingEPSS 0.4%CVE-2018-1992MEDIUMThe IBM Power 9 OP910, OP920, and FW910 boot firmware's bootloader is responsible for loading and validating the initial boot firmware imageEPSS 0.4%CVE-2019-4620HIGHIBM MQ Appliance 8.0 and 9.0 LTS could allow a local attacker to bypass security restrictions caused by improper validation of environment vEPSS 0.4%CVE-2026-79723MEDIUMLangflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetchesEPSS 0.4%CVE-2020-4756MEDIUMIBM Spectrum Scale V4.2.0.0 through V4.2.3.23 and V5.0.0.0 through V5.0.5.2 as well as IBM Elastic Storage System 6.0.0 through 6.0.1.0 coulEPSS 0.4%CVE-2017-1787MEDIUMIBM Publishing Engine 2.1.2 and 6.0.5 contains an undisclosed vulnerability that could allow a local user with administrative privileges to EPSS 0.4%CVE-2019-4259MEDIUMA security vulnerability has been identified in IBM Spectrum Scale 4.1.1, 4.2.0, 4.2.1, 4.2.2, 4.2.3, and 5.0.0 with CES stack enabled that EPSS 0.4%CVE-2024-55895LOWIBM InfoSphere Information Server information disclosureEPSS 0.4%CVE-2019-4145HIGHIBM Security Access Manager 9.0.1 through 9.0.6 could reveal highly sensitive in specialized conditions to a local user which could be used EPSS 0.4%CVE-2025-25023MEDIUMIBM Security Guardium information disclosureEPSS 0.4%CVE-2019-4132MEDIUMIBM Cloud Automation Manager 3.1.2 could allow a user to be impropertly redirected and obtain sensitive information rather than receive a 40EPSS 0.4%CVE-2018-1498MEDIUMIBM Security Guardium EcoSystem 10.5 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 14122EPSS 0.4%CVE-2020-4829HIGHIBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerability in the ksu user command to gain root privileges. IBM X-FoEPSS 0.4%CVE-2024-49816MEDIUMIBM Security Guardium Key Lifecycle Manager information disclosureEPSS 0.4%CVE-2024-5591MEDIUMIBM Jazz Foundation information disclosureEPSS 0.4%CVE-2023-40695MEDIUMIBM Cognos Controller session fixationEPSS 0.4%CVE-2024-49798MEDIUMIBM ApplinX Information DisclosureEPSS 0.4%CVE-2022-40746HIGHIBM i Access Family 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.0 could allow a local authenticated attacker to execute arbitrary code on EPSS 0.4%CVE-2019-4381MEDIUMIBM i 7.27.3 Clustering could allow a local attacker to obtain sensitive information, caused by the use of advanced node failure detection uEPSS 0.4%