Vulnerabilidades en IBM

5658 resultados
Análisis Vexday

Com 4.716 CVEs catalogadas, o portfólio da IBM acumula um volume expressivo de vulnerabilidades, embora sua taxa de exploração ativa — 5 entradas no catálogo KEV da CISA, representando 0,11% do total — esteja abaixo da média geral do catálogo (0,45%), o que sugere menor aproveitamento ativo em comparação proporcional com outros vendors. A atenção deve se concentrar em CVE-2022-47986, cuja pontuação EPSS de 0,9997 indica probabilidade extremamente elevada de exploração ativa, tornando-a prioridade imediata de mitigação. As 92 CVEs críticas e 18 com PoC pública ampliam a superfície de risco concreto, especialmente considerando que 129 novas vulnerabilidades surgiram nos últimos 90 dias, indicando ritmo relevante de descoberta recente. O tipo de falha mais recorrente, CWE-79 (Cross-Site Scripting), aponta para fragilidades persistentes na camada de apresentação que exigem atenção continuada em práticas de desenvolvimento e validação de entrada.

CVE-2018-1923HIGHIBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is affected by buffer overflow vulnerability thaEPSS 0.5%CVE-2018-1622MEDIUMIBM Security Privileged Identity Manager Virtual Appliance 2.2.1 is vulnerable to cross-site request forgery which could allow an attacker tEPSS 0.5%CVE-2021-38982MEDIUMIBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arEPSS 0.5%CVE-2022-42438HIGHIBM Cloud Pak for Multicloud Management Monitoring privilege escalationEPSS 0.5%CVE-2021-29878MEDIUMIBM Business Automation Workflow 18.0, 19.0, 20.0, and 21.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed EPSS 0.5%CVE-2019-4750MEDIUMIBM Cloud App Management 2019.3.0 and 2019.4.0 is vulnerable to cross-site request forgery which could allow an attacker to execute maliciouEPSS 0.5%CVE-2020-4942MEDIUMIBM Curam Social Program Management 7.0.9 and 7.0.11 is vulnerable to cross-site request forgery which could allow an attacker to execute maEPSS 0.5%CVE-2022-43917MEDIUMIBM WebSphere Application Server information disclosureEPSS 0.5%CVE-2019-4322HIGHIBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could EPSS 0.5%CVE-2019-4154HIGHIBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could EPSS 0.5%CVE-2021-38859MEDIUMIBM Security Verify Privilege information disclosureEPSS 0.5%CVE-2019-4016HIGHIBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could EPSS 0.5%CVE-2019-4015HIGHIBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could EPSS 0.5%CVE-2026-8056HIGHParameter Injection Vulnerability in API Graph Execution EngineEPSS 0.5%CVE-2017-1746—IBM Jazz for Service Management (IBM Tivoli Components 1.1.3) is vulnerable to cross-site request forgery which could allow an attacker to eEPSS 0.5%CVE-2026-7873CRITICALCode Injection Vulnerability in Code Validation EndpointEPSS 0.5%CVE-2026-13435CRITICALPython Interpreter Sandbox Bypass Leading to Sensitive Data ExposureEPSS 0.5%CVE-2026-8635CRITICALArbitrary Code Execution in Python Interpreter ComponentEPSS 0.5%CVE-2017-1631—IBM Jazz for Service Management (IBM Tivoli Components 1.1.3) is vulnerable to cross-site request forgery which could allow an attacker to eEPSS 0.5%CVE-2019-4088HIGHIBM Spectrum Protect Servers 7.1 and 8.1 and Storage Agents could allow a local attacker to gain elevated privileges on the system, caused bEPSS 0.5%