Vulnerabilities in IBM

5,658 results
Vexday analysis

Com 4.716 CVEs catalogadas, o portfólio da IBM acumula um volume expressivo de vulnerabilidades, embora sua taxa de exploração ativa — 5 entradas no catálogo KEV da CISA, representando 0,11% do total — esteja abaixo da média geral do catálogo (0,45%), o que sugere menor aproveitamento ativo em comparação proporcional com outros vendors. A atenção deve se concentrar em CVE-2022-47986, cuja pontuação EPSS de 0,9997 indica probabilidade extremamente elevada de exploração ativa, tornando-a prioridade imediata de mitigação. As 92 CVEs críticas e 18 com PoC pública ampliam a superfície de risco concreto, especialmente considerando que 129 novas vulnerabilidades surgiram nos últimos 90 dias, indicando ritmo relevante de descoberta recente. O tipo de falha mais recorrente, CWE-79 (Cross-Site Scripting), aponta para fragilidades persistentes na camada de apresentação que exigem atenção continuada em práticas de desenvolvimento e validação de entrada.

CVE-2022-40228LOWIBM DataPower Gateway session fixationEPSS 0.3%CVE-2026-17617HIGHServer-Side Request Forgery (SSRF) in IBM Application Gateway OperatorEPSS 0.3%CVE-2020-4717MEDIUMA vulnerability exists in IBM SPSS Modeler Subscription Installer that allows a user with create symbolic link permission to write arbitraryEPSS 0.3%CVE-2020-4411HIGHThe Spectrum Scale 4.2.0.0 through 4.2.3.21 and 5.0.0.0 through 5.0.4.3 file system component is affected by a denial of service vulnerabiliEPSS 0.3%CVE-2026-14996HIGHMultiple vulnerabilities in IBM Aspera FaspexEPSS 0.3%CVE-2026-16480MEDIUMIBM® Db2® is affected by an improper authorization vulnerability in the certain command, allowing a non-privileged user to bypass authority checks and modify database catalog data.EPSS 0.3%CVE-2026-1577MEDIUMIBM® Db2® is vulnerable to a denial of service with a specially crafted query involving multiple subqueriesEPSS 0.3%CVE-2019-4093MEDIUMIBM Tivoli Storage Manager (IBM Spectrum Protect 8.1.7) could allow a user to restore files and directories using IBM Spectrum Prootect ClieEPSS 0.3%CVE-2019-4054MEDIUMIBM QRadar SIEM 7.2 and 7.3 could allow a local user to obtain sensitive information when exporting content that could aid an attacker in fuEPSS 0.3%CVE-2026-14893HIGHIBM Instana Observability is affected by multiple Prototype Pollution within Instana Agent container imageEPSS 0.3%CVE-2024-31892HIGHIBM Storage Scale SQL injectionEPSS 0.3%CVE-2022-46774MEDIUMIBM Manage Application security bypassEPSS 0.3%CVE-2025-13219MEDIUMMultiple vulnerabilities in IBM Aspera OrchestratorEPSS 0.3%CVE-2019-4385MEDIUMIBM Spectrum Protect Plus 10.1.2 may display the vSnap CIFS password in the IBM Spectrum Protect Plus Joblog. This can result in an attackerEPSS 0.3%CVE-2025-13925MEDIUMMultiple vulnerabilities in IBM Aspera ConsoleEPSS 0.3%CVE-2024-47104MEDIUMIBM i incorrect privilege assignmentEPSS 0.3%CVE-2023-47741MEDIUMIBM i information disclosureEPSS 0.3%CVE-2025-66487LOWMultiple vulnerabilities have been addressed in IBM Aspera SharesEPSS 0.3%CVE-2026-8852MEDIUMIBM HTTP Server is affected by multiple vulnerabilitiesEPSS 0.3%CVE-2025-36354HIGHIBM Security Verify Access command executionEPSS 0.3%