Vulnerabilidades en IBM

5658 resultados
Análisis Vexday

Com 4.716 CVEs catalogadas, o portfólio da IBM acumula um volume expressivo de vulnerabilidades, embora sua taxa de exploração ativa — 5 entradas no catálogo KEV da CISA, representando 0,11% do total — esteja abaixo da média geral do catálogo (0,45%), o que sugere menor aproveitamento ativo em comparação proporcional com outros vendors. A atenção deve se concentrar em CVE-2022-47986, cuja pontuação EPSS de 0,9997 indica probabilidade extremamente elevada de exploração ativa, tornando-a prioridade imediata de mitigação. As 92 CVEs críticas e 18 com PoC pública ampliam a superfície de risco concreto, especialmente considerando que 129 novas vulnerabilidades surgiram nos últimos 90 dias, indicando ritmo relevante de descoberta recente. O tipo de falha mais recorrente, CWE-79 (Cross-Site Scripting), aponta para fragilidades persistentes na camada de apresentação que exigem atenção continuada em práticas de desenvolvimento e validação de entrada.

CVE-2026-18715MEDIUMIBM i is Affected By Multiple Vulnerabilities in WebSphere Application Server LibertyEPSS 0.4%CVE-2026-6936MEDIUMIBM i is Affected by a Denial of Service Vulnerability []EPSS 0.4%CVE-2026-3676MEDIUMThere are multiple vulnerabilities in IBM DB2 bundled with IBM Application Performance Management products.EPSS 0.4%CVE-2024-54178MEDIUMMultiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data.EPSS 0.4%CVE-2026-11906MEDIUMIBM® Db2® federated server is vulnerable to a denial of service due to improper neutralization of special elements in the data query logic of XMLTable-derived columns by autheticated userEPSS 0.4%CVE-2020-4553HIGHIBM i2 Analyst Notebook 9.2.1 and 9.2.2 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption.EPSS 0.4%CVE-2025-36097HIGHIBM WebSphere Application Server denial of serviceEPSS 0.4%CVE-2020-4552HIGHIBM i2 Analyst Notebook 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuaEPSS 0.4%CVE-2023-50950LOWIBM QRadar information disclosureEPSS 0.4%CVE-2020-4550HIGHIBM i2 Analyst Notebook 9.2.1 and 9.2.2 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption.EPSS 0.4%CVE-2020-4554HIGHIBM i2 Analyst Notebook 9.2.1 and 9.2.2 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption.EPSS 0.4%CVE-2020-4551HIGHIBM i2 Analyst Notebook 9.2.1 and 9.2.2 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption.EPSS 0.4%CVE-2020-4549HIGHIBM i2 Analyst Notebook 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuaEPSS 0.4%CVE-2024-56339LOWIBM WebSphere Application Server information disclosureEPSS 0.4%CVE-2024-39751MEDIUMIBM InfoSphere Information Server information disclosureEPSS 0.4%CVE-2026-18499HIGHIBM WebSphere Application Server Liberty is affected by a privilege escalationEPSS 0.4%CVE-2026-16335HIGHDataStage on Cloud Pak for Data has several vulnerabilities due to open source softwareEPSS 0.4%CVE-2020-4263HIGHIBM i2 Intelligent Analyis Platform 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruptioEPSS 0.4%CVE-2025-33076HIGHIBM Engineering Systems Design Rhapsody code executionEPSS 0.4%CVE-2020-4258HIGHIBM i2 Intelligent Analyis Platform 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruptioEPSS 0.4%