Vulnerabilities in IBM

5,658 results
Vexday analysis

Com 4.716 CVEs catalogadas, o portfólio da IBM acumula um volume expressivo de vulnerabilidades, embora sua taxa de exploração ativa — 5 entradas no catálogo KEV da CISA, representando 0,11% do total — esteja abaixo da média geral do catálogo (0,45%), o que sugere menor aproveitamento ativo em comparação proporcional com outros vendors. A atenção deve se concentrar em CVE-2022-47986, cuja pontuação EPSS de 0,9997 indica probabilidade extremamente elevada de exploração ativa, tornando-a prioridade imediata de mitigação. As 92 CVEs críticas e 18 com PoC pública ampliam a superfície de risco concreto, especialmente considerando que 129 novas vulnerabilidades surgiram nos últimos 90 dias, indicando ritmo relevante de descoberta recente. O tipo de falha mais recorrente, CWE-79 (Cross-Site Scripting), aponta para fragilidades persistentes na camada de apresentação que exigem atenção continuada em práticas de desenvolvimento e validação de entrada.

CVE-2024-39723MEDIUMIBM FlashSystem denial of serviceEPSS 0.2%CVE-2020-5021MEDIUMIBM Spectrum Protect Plus 10.1.0 through 10.1.6 does not invalidate session after a password reset which could allow a local user to impersoEPSS 0.2%CVE-2026-18341MEDIUMIBM i is Affected By Buffer Overflow Vulnerability []EPSS 0.2%CVE-2025-36016MEDIUMIBM Process Mining HTTP open redirectEPSS 0.2%CVE-2022-41297MEDIUMIBM Db2U cross-site request forgeryEPSS 0.2%CVE-2020-4387MEDIUMIBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to obtain sensitiEPSS 0.2%CVE-2024-51451MEDIUMMultiple Vulnerabilities in IBM Concert SoftwareEPSS 0.2%CVE-2024-45071MEDIUMIBM WebSphere Application Server cross-site scriptingEPSS 0.2%CVE-2018-1877MEDIUMIBM Robotic Process Automation with Automation Anywhere 11 could store highly sensitive information in the form of unencrypted passwords thaEPSS 0.2%CVE-2025-36122MEDIUMIBM® Db2® is vulnerable to a denial of service with a specially crafted query when stmtheap is set to automaticEPSS 0.2%CVE-2024-31914MEDIUMIBM Sterling B2B Integrator cross-site scriptingEPSS 0.2%CVE-2026-9762HIGHIBM® Data Server driver for JDBC and SQLJ is vulnerable to remote code execution when jdbc url is under user controlEPSS 0.2%CVE-2024-40690MEDIUMIBM InfoSphere Server cross-site scriptingEPSS 0.2%CVE-2020-4631MEDIUMIBM Spectrum Protect Plus 10.1.0 through 10.1.6 agent files, in non-default configurations, on Windows are assigned access to everyone with EPSS 0.2%CVE-2019-4351LOWIBM Maximo Anywhere 7.6.4.0 applications could disclose sensitive information to a user with physical access to the device. IBM X-Force ID: EPSS 0.2%CVE-2026-16708HIGHIBM Db2 Mirror for i is affected by multiple vulnerabilitiesEPSS 0.2%CVE-2017-1575MEDIUMIBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) uses weaker than expected cryptographic algoritEPSS 0.2%CVE-2025-36255HIGHDS8900F and DS8A00 Privilege EscalationEPSS 0.2%CVE-2025-36010MEDIUMIBM Db2 for Linux denial of serviceEPSS 0.2%CVE-2022-22380MEDIUMIBM Security Verify Privilege improper authenticationEPSS 0.2%