Vulnerabilidades en IBM Corporation

288 resultados
Análisis Vexday

O portfólio de vulnerabilidades catalogadas para IBM Corporation totaliza 288 CVEs, com taxa de exploração ativa abaixo da média geral do catálogo — nenhuma entrada consta no CISA KEV e não há registros de severidade crítica ou novas ocorrências nos últimos 90 dias, o que indica estabilidade no volume de exposições recentes. Ainda assim, a presença de 4 CVEs com prova de conceito pública exige atenção contínua, pois facilita a reprodução de ataques por agentes com capacidade técnica limitada. O destaque de maior risco no momento é CVE-2017-1092, que apresenta pontuação EPSS de 0,7577 — valor elevado que sinaliza probabilidade estatisticamente relevante de exploração —, sugerindo que, apesar da ausência de confirmação no KEV, essa vulnerabilidade deve ser tratada como prioridade em processos de remediação e monitoramento.

CVE-2017-1155IBM Algorithmics One-Algo Risk Application 4.9.1, 5.0, and 5.1.0 could allow a user to gain access to another user's reports using a specialEPSS 1.3%CVE-2016-8982IBM InfoSphere Information Server stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized paEPSS 1.3%CVE-2017-1153IBM TRIRIGA Report Manager 3.2 through 3.5 contains a vulnerability that could allow an authenticated user to execute actions that they do nEPSS 1.3%CVE-2016-9990IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web EPSS 1.3%CVE-2016-3020IBM Security Access Manager for Web 7.0.0, 8.0.0, and 9.0.0 could allow a remote attacker to bypass security restrictions, caused by impropeEPSS 1.2%CVE-2016-6116IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properlEPSS 1.2%CVE-2016-3043IBM Security Access Manager for Web could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable EPSS 1.2%CVE-2016-5966IBM Security Privileged Identity Manager Virtual Appliance could allow a remote attacker to obtain sensitive information, caused by the failEPSS 1.2%CVE-2016-8966IBM BigFix Inventory v9 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict EPSS 1.2%CVE-2017-1142IBM Kenexa LCMS Premier on Cloud 9.x and 10.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set thEPSS 1.2%CVE-2016-9724IBM QRadar 7.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remoEPSS 1.2%CVE-2016-8974IBM Rhapsody DM 4.0, 5.0 and 6.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processinEPSS 1.2%CVE-2017-1103IBM Team Concert (RTC) is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML dataEPSS 1.2%CVE-2019-4301BigFix Self-Service Application (SSA) is vulnerable to arbitrary code execution if Javascript code is included in Running Message or Post MeEPSS 1.2%CVE-2016-5994IBM InfoSphere Information Server contains a vulnerability that would allow an authenticated user to browse any file on the engine tier, andEPSS 1.2%CVE-2016-0307IBM Connections 5.5 and earlier allows remote attackers to obtain sensitive information by reading stack traces in returned responses.EPSS 1.2%CVE-2017-1156IBM WebSphere Portal 8.5 and 9.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a vEPSS 1.1%CVE-2016-9000IBM InfoSphere DataStage is vulnerable to cross-frame scripting, caused by insufficient HTML iframe protection. A remote attacker could explEPSS 1.1%CVE-2016-3023IBM Security Access Manager for Web could allow an unauthenticated user to gain access to sensitive information by entering invalid file namEPSS 1.1%CVE-2016-5883IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web EPSS 1.1%