Vulnerabilidades en IBM

5652 resultados
Análisis Vexday

Com 4.716 CVEs catalogadas, o portfólio da IBM acumula um volume expressivo de vulnerabilidades, embora sua taxa de exploração ativa — 5 entradas no catálogo KEV da CISA, representando 0,11% do total — esteja abaixo da média geral do catálogo (0,45%), o que sugere menor aproveitamento ativo em comparação proporcional com outros vendors. A atenção deve se concentrar em CVE-2022-47986, cuja pontuação EPSS de 0,9997 indica probabilidade extremamente elevada de exploração ativa, tornando-a prioridade imediata de mitigação. As 92 CVEs críticas e 18 com PoC pública ampliam a superfície de risco concreto, especialmente considerando que 129 novas vulnerabilidades surgiram nos últimos 90 dias, indicando ritmo relevante de descoberta recente. O tipo de falha mais recorrente, CWE-79 (Cross-Site Scripting), aponta para fragilidades persistentes na camada de apresentação que exigem atenção continuada em práticas de desenvolvimento e validação de entrada.

CVE-2023-49877MEDIUMIBM System Storage Virtualization Engine information disclosureEPSS 0.8%CVE-2019-4280MEDIUMIBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 displays sensitive information in HTTP requests which could be used in further attacks agaEPSS 0.8%CVE-2019-4698HIGHIBM Security Guardium Data Encryption (GDE) 3.0.0.2 does not require that users should have strong passwords by default, which makes it easiEPSS 0.8%CVE-2020-4406MEDIUMIBM Spectrum Protect Client 8.1.7.0 through 8.1.9.1 (Linux and Windows), 8.1.9.0 trough 8.1.9.1 (AIX) and IBM Spectrum Protect for Space ManEPSS 0.8%CVE-2026-14958CRITICALOS command injection in IBM Aspera FaspexEPSS 0.8%CVE-2021-20429LOWIBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 could disclose sensitive information due an overly permissive cross-domain policy. IBEPSS 0.8%CVE-2020-4529HIGHIBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker toEPSS 0.8%CVE-2020-4547MEDIUMIBM Jazz Foundation products could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a maEPSS 0.8%CVE-2022-22409MEDIUMIBM Aspera Faspex information disclosureEPSS 0.8%CVE-2019-4271LOWIBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin console is vulnerable to a Client-side HTTP parameter pollution vulnerability.EPSS 0.8%CVE-2021-39019MEDIUMIBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could disclose highly sensitive information througEPSS 0.8%CVE-2023-24971HIGHIBM B2B Advanced Communication denial of serviceEPSS 0.8%CVE-2024-22353MEDIUMIBM WebSphere Application Server Liberty denial of serviceEPSS 0.8%CVE-2020-4303MEDIUMIBM WebSphere Application Server - Liberty 17.0.0.3 through 20.0.0.3 is vulnerable to cross-site scripting. This vulnerability allows users EPSS 0.8%CVE-2020-4304MEDIUMIBM WebSphere Application Server - Liberty 17.0.0.3 through 20.0.0.3 is vulnerable to cross-site scripting. This vulnerability allows users EPSS 0.8%CVE-2023-43044MEDIUMIBM License Metric Tool directory traversalEPSS 0.8%CVE-2019-4679MEDIUMIBM Content Navigator 3.0CD could allow an authenticated user to gain information about the hosting operating system and version that could EPSS 0.8%CVE-2019-4593MEDIUMIBM QRadar 7.3.0 to 7.3.3 Patch 2 generates an error message that includes sensitive information that could be used in further attacks againEPSS 0.8%CVE-2020-4484MEDIUMIBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 could disclose sensitive information to an authenticated user that could bEPSS 0.8%CVE-2020-4312MEDIUMIBM Sterling B2B Integrator Standard Edition 5.2.0.0 trough 6.0.3.1 could allow an authenticated user to obtain sensitive information from aEPSS 0.8%