Vulnerabilities in IBM

4,759 results
Vexday analysis

Com 4.716 CVEs catalogadas, o portfólio da IBM acumula um volume expressivo de vulnerabilidades, embora sua taxa de exploração ativa — 5 entradas no catálogo KEV da CISA, representando 0,11% do total — esteja abaixo da média geral do catálogo (0,45%), o que sugere menor aproveitamento ativo em comparação proporcional com outros vendors. A atenção deve se concentrar em CVE-2022-47986, cuja pontuação EPSS de 0,9997 indica probabilidade extremamente elevada de exploração ativa, tornando-a prioridade imediata de mitigação. As 92 CVEs críticas e 18 com PoC pública ampliam a superfície de risco concreto, especialmente considerando que 129 novas vulnerabilidades surgiram nos últimos 90 dias, indicando ritmo relevante de descoberta recente. O tipo de falha mais recorrente, CWE-79 (Cross-Site Scripting), aponta para fragilidades persistentes na camada de apresentação que exigem atenção continuada em práticas de desenvolvimento e validação de entrada.

CVE-2021-38960MEDIUMIBM OPENBMC OP920, OP930, and OP940 could allow an unauthenticated user to obtain sensitive information. IBM X-Force ID: 212047.EPSS 1.1%CVE-2021-29854MEDIUMIBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST hEPSS 1.1%CVE-2018-1774HIGHIBM API Connect 5.0.0.0, 5.0.8.4, 2018.1 and 2018.3.6 is vulnerable to CSV injection via the developer portal and analytics that could contaEPSS 1.1%CVE-2019-4575MEDIUMIBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.2.0 through 3.2.9 is vulnerable to SQL injection. A remote attacEPSS 1.1%CVE-2024-56346CRITICALIBM AIX command executionEPSS 1.1%CVE-2019-4297MEDIUMIBM Robotic Process Automation with Automation Anywhere 11 could allow a remote authenticated attacker to conduct an LDAP injection. By usinEPSS 1.1%CVE-2017-1257IBM Security Guardium 10.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on thEPSS 1.1%CVE-2017-1374Sensitive data can be exposed in the IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 that can lead to an attacker gaining unauthorized acEPSS 1.1%CVE-2019-4560MEDIUMIBM MQ and IBM MQ Appliance 9.1 CD, 9.1 LTS, 9.0 LTS, and 8.0 is vulnerable to a denial of service attack caused by channels processing poorEPSS 1.1%CVE-2021-29851MEDIUMIBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. IBM EPSS 1.1%CVE-2020-4383MEDIUMIBM Spectrum Scale for IBM Elastic Storage Server 5.3.0 through 5.3.5 could allow an authenticated user to cause a denial of service during EPSS 1.1%CVE-2020-4376MEDIUMIBM MQ, IBM MQ Appliance, IBM MQ for HPE NonStop 8.0.4 and 8.1.0 could allow an attacker to cause a denial of service caused by an error witEPSS 1.1%CVE-2019-4547MEDIUMIBM Security Directory Server 6.4.0 generates an error message that includes sensitive information about its environment, users, or associatEPSS 1.1%CVE-2020-4908MEDIUMIBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 returns the product version and release information on the logEPSS 1.1%CVE-2017-1421IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alteEPSS 1.1%CVE-2023-42004HIGHIBM Security Guardium CSV injectionEPSS 1.1%CVE-2023-29258MEDIUMIBM Db2 denial of serviceEPSS 1.1%CVE-2023-38727MEDIUMIBM Db2 denial of serviceEPSS 1.1%CVE-2023-40687MEDIUMIBM Db2 denial of serviceEPSS 1.1%CVE-2020-4912MEDIUMIBM Cloud Pak System 2.3 Self Service Console could allow a privilege escalation by capturing the user request URL when logged in as a priviEPSS 1.1%