Vulnerabilities in IBM

5,658 results
Vexday analysis

Com 4.716 CVEs catalogadas, o portfólio da IBM acumula um volume expressivo de vulnerabilidades, embora sua taxa de exploração ativa — 5 entradas no catálogo KEV da CISA, representando 0,11% do total — esteja abaixo da média geral do catálogo (0,45%), o que sugere menor aproveitamento ativo em comparação proporcional com outros vendors. A atenção deve se concentrar em CVE-2022-47986, cuja pontuação EPSS de 0,9997 indica probabilidade extremamente elevada de exploração ativa, tornando-a prioridade imediata de mitigação. As 92 CVEs críticas e 18 com PoC pública ampliam a superfície de risco concreto, especialmente considerando que 129 novas vulnerabilidades surgiram nos últimos 90 dias, indicando ritmo relevante de descoberta recente. O tipo de falha mais recorrente, CWE-79 (Cross-Site Scripting), aponta para fragilidades persistentes na camada de apresentação que exigem atenção continuada em práticas de desenvolvimento e validação de entrada.

CVE-2026-17268MEDIUMIBM i is Affected By Multiple Vulnerabilities in Navigator for iEPSS 0.3%CVE-2025-27907MEDIUMIBM WebSphere Application Server server-side request forgeryEPSS 0.3%CVE-2021-38927HIGHIBM Aspera Console cross-site scriptingEPSS 0.3%CVE-2023-22870MEDIUMIBM Aspera Faspex information disclosureEPSS 0.3%CVE-2020-4606MEDIUMIBM Security Verify Privilege Manager 10.8 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A local EPSS 0.3%CVE-2018-1650MEDIUMIBM QRadar SIEM 7.2 and 7.3 uses hard-coded credentials which could allow an attacker to bypass the authentication configured by the adminisEPSS 0.3%CVE-2026-16432HIGHDataStage on Cloud Pak for Data has several vulnerabilities due to open source softwareEPSS 0.3%CVE-2022-35282MEDIUMIBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted EPSS 0.3%CVE-2016-5893—IBM Sterling B2B Integrator Standard Edition 5.2 allows web pages to be stored locally which can be read by another user on the system. IBM EPSS 0.3%CVE-2026-17207MEDIUMIBM i is Affected By Denial of Service Vulnerabilities in NFS [, ]EPSS 0.3%CVE-2026-8856HIGHIBM HTTP Server is affected by multiple vulnerabilitiesEPSS 0.3%CVE-2026-16964MEDIUMVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.3%CVE-2017-1714—IBM Notes and Domino NSD 8.5 and 9.0 could allow an authenticated local user without administrative privileges to gain System privilege. IBMEPSS 0.3%CVE-2020-4414MEDIUMIBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local attacker to perform unEPSS 0.3%CVE-2023-46175MEDIUMIBM Cloud Pak for Multicloud Management information disclosureEPSS 0.3%CVE-2023-23472LOWIBM InfoSphere Information Server information disclosureEPSS 0.3%CVE-2026-15064HIGHIBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilitiesEPSS 0.3%CVE-2025-36428MEDIUMIBM Db2 Denial of ServiceEPSS 0.3%CVE-2024-39728MEDIUMIBM Datacap Navigator cross-site scriptingEPSS 0.3%CVE-2026-15325HIGHIBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilitiesEPSS 0.3%