Vulnerabilidades em IBM

4.759 resultados
Análise Vexday

Com 4.716 CVEs catalogadas, o portfólio da IBM acumula um volume expressivo de vulnerabilidades, embora sua taxa de exploração ativa — 5 entradas no catálogo KEV da CISA, representando 0,11% do total — esteja abaixo da média geral do catálogo (0,45%), o que sugere menor aproveitamento ativo em comparação proporcional com outros vendors. A atenção deve se concentrar em CVE-2022-47986, cuja pontuação EPSS de 0,9997 indica probabilidade extremamente elevada de exploração ativa, tornando-a prioridade imediata de mitigação. As 92 CVEs críticas e 18 com PoC pública ampliam a superfície de risco concreto, especialmente considerando que 129 novas vulnerabilidades surgiram nos últimos 90 dias, indicando ritmo relevante de descoberta recente. O tipo de falha mais recorrente, CWE-79 (Cross-Site Scripting), aponta para fragilidades persistentes na camada de apresentação que exigem atenção continuada em práticas de desenvolvimento e validação de entrada.

CVE-2018-1706MEDIUMIBM Spectrum Symphony 7.2.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in tEPSS 0.7%CVE-2017-1792MEDIUMIBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows usersEPSS 0.7%CVE-2018-1610MEDIUMIBM Rational DOORS Next Generation 5.0 through 5.0.2 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allowsEPSS 0.7%CVE-2017-1114MEDIUMIBM Campaign 9.1, 9.1.2, and 10 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code inEPSS 0.7%CVE-2022-35284MEDIUMIBM Security Verify Information Queue 10.0.2 could disclose sensitive information due to a missing or insecure SameSite attribute for a sensEPSS 0.7%CVE-2021-29773MEDIUMIBM Security Guardium 10.6 and 11.3 could allow a remote authenticated attacker to obtain sensitive information or modify user details causeEPSS 0.7%CVE-2019-4589MEDIUMIBM Cognos Analytics 11.0 and 11.1 is vulnerable to privlege escalation where the "My schedules and subscriptions" page is visible and accesEPSS 0.7%CVE-2021-39063MEDIUMIBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out priEPSS 0.7%CVE-2022-22396MEDIUMCredentials are printed in clear text in the IBM Spectrum Protect Plus 10.1.0.0 through 10.1.9.3 virgo log file in certain cases. CredentialEPSS 0.7%CVE-2019-4692MEDIUMIBM Security Guardium Data Encryption (GDE) 3.0.0.2 discloses sensitive information to unauthorized users. The information can be used to moEPSS 0.7%CVE-2021-38874MEDIUMIBM QRadar SIEM 7.3, 7.4, and 7.5 allows for users to access information across tenant and domain boundaries in some situations. IBM X-ForceEPSS 0.7%CVE-2019-4701MEDIUMIBM Security Guardium Data Encryption (GDE) 3.0.0.2 is deployed with active debugging code that can create unintended entry points. IBM X-FoEPSS 0.7%CVE-2023-49878MEDIUMIBM System Storage Virtualization Engine information disclosureEPSS 0.7%CVE-2023-27284HIGHIBM Aspera code executionEPSS 0.7%CVE-2023-27286HIGHIBM Aspera code executionEPSS 0.7%CVE-2024-51470MEDIUMIBM MQ denial of serviceEPSS 0.7%CVE-2021-20407MEDIUMIBM Security Verify Information Queue information disclosureEPSS 0.7%CVE-2022-40237MEDIUMIBM MQ for HPE NonStop denial of serviceEPSS 0.7%CVE-2020-4916MEDIUMIBM Cloud Pak System 2.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the WeEPSS 0.7%CVE-2021-39080MEDIUMDue to weak obfuscation, IBM Cognos Analytics Mobile for Android application prior to version 1.1.14 , an attacker could be able to reverse EPSS 0.7%