Vulnerabilities in IBM

5,658 results
Vexday analysis

Com 4.716 CVEs catalogadas, o portfólio da IBM acumula um volume expressivo de vulnerabilidades, embora sua taxa de exploração ativa — 5 entradas no catálogo KEV da CISA, representando 0,11% do total — esteja abaixo da média geral do catálogo (0,45%), o que sugere menor aproveitamento ativo em comparação proporcional com outros vendors. A atenção deve se concentrar em CVE-2022-47986, cuja pontuação EPSS de 0,9997 indica probabilidade extremamente elevada de exploração ativa, tornando-a prioridade imediata de mitigação. As 92 CVEs críticas e 18 com PoC pública ampliam a superfície de risco concreto, especialmente considerando que 129 novas vulnerabilidades surgiram nos últimos 90 dias, indicando ritmo relevante de descoberta recente. O tipo de falha mais recorrente, CWE-79 (Cross-Site Scripting), aponta para fragilidades persistentes na camada de apresentação que exigem atenção continuada em práticas de desenvolvimento e validação de entrada.

CVE-2026-17423HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.3%CVE-2024-28761MEDIUMIBM App Connect Enterprise HTML injectionEPSS 0.3%CVE-2019-4349LOWIBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 applications can be installed on a deprecated operating system version that couldEPSS 0.3%CVE-2017-1190—IBM Emptoris Strategic Supply Management Platform 10.x and 10.1 could allow a local user with special access roles to execute arbitrary codeEPSS 0.3%CVE-2025-1759MEDIUMIBM Concert Software information disclosureEPSS 0.3%CVE-2024-49808MEDIUMIBM Sterling Connect:Direct Web Services improper authorizationEPSS 0.3%CVE-2018-1985MEDIUMIBM Trusteer Rapport/Apex 3.6.1908.22 contains an unused legacy driver which could allow a user with administrator privileges to cause a bufEPSS 0.3%CVE-2025-36359HIGHIBM DevOps Loop is susceptible to an Insufficient Session Expiration vulnerability.EPSS 0.3%CVE-2017-1441—IBM Emptoris Services Procurement 10.0.0.5 could allow a local user to view sensitive information stored locally due to improper access contEPSS 0.3%CVE-2017-1349—IBM Sterling B2B Integrator Standard Edition 5.2 stores potentially sensitive information from HTTP sessions that could be read by a local uEPSS 0.3%CVE-2023-38010MEDIUMMultiple Vulnerabilities in IBM Cloud Pak SystemEPSS 0.3%CVE-2021-29740HIGHIBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.3 system core component is affected by a format string security vulnerabiliEPSS 0.3%CVE-2016-5960—IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores user credentials in plain in clear text which can be read by a local user. IEPSS 0.3%CVE-2018-1724MEDIUMIBM Spectrum LSF 9.1.1 9.1.2, 9.1.3, and 10.1 could allow a local user to change their job user at job submission time due to improper file EPSS 0.3%CVE-2026-12354HIGHIBM MQ Resource Adapter IVT message-driven bean is vulnerable to remote code execution via JNDI injectionEPSS 0.3%CVE-2026-11716HIGHIBM MQ for HPE NonStop is vulnerable to a denial of service attackEPSS 0.3%CVE-2026-11381HIGHIBM MQ for HPE NonStop is vulnerable to a denial of service issueEPSS 0.3%CVE-2025-25048MEDIUMIBM Jazz Foundation path traversalEPSS 0.3%CVE-2024-45670MEDIUMIBM Security SOAR weak password recovery mechanismEPSS 0.3%CVE-2020-4338MEDIUMIBM MQ 9.1.4 could allow a local attacker to obtain sensitive information by inclusion of sensitive data within runmqras data. IBM X-Force IEPSS 0.3%