Vulnerabilities in IBM

5,658 results
Vexday analysis

Com 4.716 CVEs catalogadas, o portfólio da IBM acumula um volume expressivo de vulnerabilidades, embora sua taxa de exploração ativa — 5 entradas no catálogo KEV da CISA, representando 0,11% do total — esteja abaixo da média geral do catálogo (0,45%), o que sugere menor aproveitamento ativo em comparação proporcional com outros vendors. A atenção deve se concentrar em CVE-2022-47986, cuja pontuação EPSS de 0,9997 indica probabilidade extremamente elevada de exploração ativa, tornando-a prioridade imediata de mitigação. As 92 CVEs críticas e 18 com PoC pública ampliam a superfície de risco concreto, especialmente considerando que 129 novas vulnerabilidades surgiram nos últimos 90 dias, indicando ritmo relevante de descoberta recente. O tipo de falha mais recorrente, CWE-79 (Cross-Site Scripting), aponta para fragilidades persistentes na camada de apresentação que exigem atenção continuada em práticas de desenvolvimento e validação de entrada.

CVE-2026-11538LOWIBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilitiesEPSS 0.2%CVE-2022-22321MEDIUMIBM MQ Appliance 9.2 CD and 9.2 LTS local messaging users stored with a password hash that provides insufficient protection. IBM X-Force ID:EPSS 0.2%CVE-2026-11918MEDIUMIBM ContextForge MCP Gateway is affected by security filter bypass via nested payload structuresEPSS 0.2%CVE-2024-40679MEDIUMIBM Db2 information disclosureEPSS 0.2%CVE-2026-3623HIGHVulnerabilities exists in IBM Netezza Performance Server Replication ServicesEPSS 0.2%CVE-2025-36033MEDIUMIBM Engineering Lifecycle Management - Global Configuration Management is vulnerable to cross-site scriptingEPSS 0.2%CVE-2026-1029MEDIUMMultiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration AgentEPSS 0.2%CVE-2023-35022LOWIBM InfoSphere Information Server improper authenticationEPSS 0.2%CVE-2025-36271MEDIUMIBM Integrated Analytics System (IIAS) is affected by a predictable salt vulnerability in Magneto componentEPSS 0.2%CVE-2025-36084MEDIUMMultiple Vulnerabilities in IBM Concert SoftwareEPSS 0.2%CVE-2026-10535HIGHIBM® Db2® is vulnerable to buffer overflow in setgid helper db2flacc which can lead to privilege escalation and instance compromise from an unprivileged shellEPSS 0.2%CVE-2023-38280HIGHIBM Power HMC privilege escalationEPSS 0.2%CVE-2025-36026MEDIUMIBM Datacap information disclosureEPSS 0.2%CVE-2025-1994HIGHIBM Cognos Command Center code executionEPSS 0.2%CVE-2026-11929HIGHSecurity vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify AccessEPSS 0.2%CVE-2024-45676MEDIUMIBM Cognos Controller file uploadEPSS 0.2%CVE-2023-28956HIGHIBM Spectrum Protect Backup-Archive Client privilege escalationEPSS 0.2%CVE-2025-33012MEDIUMIBM Db2 improper account lockoutEPSS 0.2%CVE-2022-22484MEDIUMIBM Spectrum Protect Operations Center 8.1.12 and 8.1.13 could allow a local attacker to obtain sensitive information, caused by plain text EPSS 0.2%CVE-2026-2713HIGHIBM Trusteer Rapport installer affected by uncontrolled search path element vulnerabilityEPSS 0.2%