Vulnerabilidades en IBM

5658 resultados
Análisis Vexday

Com 4.716 CVEs catalogadas, o portfólio da IBM acumula um volume expressivo de vulnerabilidades, embora sua taxa de exploração ativa — 5 entradas no catálogo KEV da CISA, representando 0,11% do total — esteja abaixo da média geral do catálogo (0,45%), o que sugere menor aproveitamento ativo em comparação proporcional com outros vendors. A atenção deve se concentrar em CVE-2022-47986, cuja pontuação EPSS de 0,9997 indica probabilidade extremamente elevada de exploração ativa, tornando-a prioridade imediata de mitigação. As 92 CVEs críticas e 18 com PoC pública ampliam a superfície de risco concreto, especialmente considerando que 129 novas vulnerabilidades surgiram nos últimos 90 dias, indicando ritmo relevante de descoberta recente. O tipo de falha mais recorrente, CWE-79 (Cross-Site Scripting), aponta para fragilidades persistentes na camada de apresentação que exigem atenção continuada em práticas de desenvolvimento e validação de entrada.

CVE-2026-17175HIGHIBM Db2 Mirror for i is affected by multiple vulnerabilitiesEPSS 0.5%CVE-2026-18713HIGHIBM i is Affected By Multiple Vulnerabilities in Navigator for iEPSS 0.5%CVE-2025-0160HIGHIBM FlashSystem code executionEPSS 0.5%CVE-2026-16839CRITICALVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.5%CVE-2021-20535MEDIUMIBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticatEPSS 0.5%CVE-2021-38911MEDIUMIBM Security Risk Manager on CP4S 1.7.0.0 stores user credentials in plain clear text which can be read by a an authenticatedl privileged usEPSS 0.5%CVE-2019-4640MEDIUMIBM Security Secret Server 10.7 processes patches, image backups and other updates without sufficiently verifying the origin and integrity oEPSS 0.5%CVE-2022-22337MEDIUMIBM Sterling B2B Integrator Standard Edition information disclosureEPSS 0.5%CVE-2026-4101HIGHSecurity Vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify AccessEPSS 0.5%CVE-2026-84070HIGHIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.5%CVE-2026-84106HIGHIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.5%CVE-2023-38735MEDIUMIBM Cognos Dashboards improper authenticationEPSS 0.5%CVE-2026-84074HIGHIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.5%CVE-2024-22345MEDIUMIBM TXSeries for Multiplatforms information disclosureEPSS 0.5%CVE-2026-7663CRITICALUnauthenticated Cross-User MCP Resource Access and Tool Execution via Streamable Transport Authorization BypassEPSS 0.5%CVE-2018-1792HIGHIBM WebSphere MQ 8.0.0.0 through 8.0.0.10, 9.0.0.0 through 9.0.0.5, 9.0.1 through 9.0.5, and 9.1.0.0 could allow a local user to inject codeEPSS 0.5%CVE-2019-4697MEDIUMIBM Security Guardium Data Encryption (GDE) 3.0.0.2 stores user credentials in plain in clear text which can be read by an authenticated useEPSS 0.5%CVE-2018-1978HIGHIBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could EPSS 0.5%CVE-2026-1376HIGHIBM i Denial of ServiceEPSS 0.5%CVE-2026-19875HIGHUnauthenticated Registration POST Endpoint Permits Admin Email Overwrite and Outbound Relay Abuse in LangflowEPSS 0.5%