Vulnerabilities in IBM

5,658 results
Vexday analysis

Com 4.716 CVEs catalogadas, o portfólio da IBM acumula um volume expressivo de vulnerabilidades, embora sua taxa de exploração ativa — 5 entradas no catálogo KEV da CISA, representando 0,11% do total — esteja abaixo da média geral do catálogo (0,45%), o que sugere menor aproveitamento ativo em comparação proporcional com outros vendors. A atenção deve se concentrar em CVE-2022-47986, cuja pontuação EPSS de 0,9997 indica probabilidade extremamente elevada de exploração ativa, tornando-a prioridade imediata de mitigação. As 92 CVEs críticas e 18 com PoC pública ampliam a superfície de risco concreto, especialmente considerando que 129 novas vulnerabilidades surgiram nos últimos 90 dias, indicando ritmo relevante de descoberta recente. O tipo de falha mais recorrente, CWE-79 (Cross-Site Scripting), aponta para fragilidades persistentes na camada de apresentação que exigem atenção continuada em práticas de desenvolvimento e validação de entrada.

CVE-2019-4691MEDIUMIBM Security Guardium Data Encryption (GDE) 3.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrarEPSS 0.4%CVE-2023-28520MEDIUMIBM Planning Analytics Local cross-site scriptingEPSS 0.4%CVE-2016-8939—IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) clients/agents store password information in the Windows Registry in a manner EPSS 0.4%CVE-2023-50956MEDIUMIBM Storage Defender - Resiliency Service information disclosureEPSS 0.4%CVE-2026-13445HIGHLangflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpointsEPSS 0.4%CVE-2026-53708MEDIUMContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)EPSS 0.4%CVE-2026-10140CRITICALCross-Tenant API Key Reuse and Billing Fraud in Langflow Voice Mode SubsystemEPSS 0.4%CVE-2026-13267HIGHSecurity vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify AccessEPSS 0.4%CVE-2019-4284MEDIUMIBM Cloud Private 2.1.0 , 3.1.0, 3.1.1, and 3.1.2 could allow a local privileged user to obtain sensitive OIDC token that is printed to log EPSS 0.4%CVE-2019-4225MEDIUMIBM PureApplication System 2.2.3.0 through 2.2.5.3 stores potentially sensitive information in log files that could be read by a local user.EPSS 0.4%CVE-2017-1681—IBM WebSphere Application Server (IBM Liberty for Java for Bluemix 3.15) could allow a local attacker to obtain sensitive information, causeEPSS 0.4%CVE-2026-13444HIGHLangflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpointsEPSS 0.4%CVE-2018-1515HIGHIBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5 and 11.1, under specific or unusual conditions, could allow a local uEPSS 0.4%CVE-2026-9225MEDIUMLangflow is vulnerable to unauthorized file system access due to path traversal and missing storage path validationEPSS 0.3%CVE-2026-17635CRITICALIBM Financial Transaction Manager (FTM) is Impacted by Multiple VulnerabilitiesEPSS 0.3%CVE-2024-49353HIGHIBM Watson Speech Services Cartridge for IBM Cloud Pak for Data denial of serviceEPSS 0.3%CVE-2026-16967HIGHIBM i is Affected By Multiple SQL Vulnerabilities [, ]EPSS 0.3%CVE-2023-47144MEDIUMIBM Tivoli Application Dependency Discovery Manager cross-site scriptingEPSS 0.3%CVE-2020-4640LOWCertain IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 configurations can result in sensitive information in tEPSS 0.3%CVE-2023-47162MEDIUMIBM Secure Proxy cross-site scriptingEPSS 0.3%