Vulnerabilidades em IBM

5.652 resultados
Análise Vexday

Com 4.716 CVEs catalogadas, o portfólio da IBM acumula um volume expressivo de vulnerabilidades, embora sua taxa de exploração ativa — 5 entradas no catálogo KEV da CISA, representando 0,11% do total — esteja abaixo da média geral do catálogo (0,45%), o que sugere menor aproveitamento ativo em comparação proporcional com outros vendors. A atenção deve se concentrar em CVE-2022-47986, cuja pontuação EPSS de 0,9997 indica probabilidade extremamente elevada de exploração ativa, tornando-a prioridade imediata de mitigação. As 92 CVEs críticas e 18 com PoC pública ampliam a superfície de risco concreto, especialmente considerando que 129 novas vulnerabilidades surgiram nos últimos 90 dias, indicando ritmo relevante de descoberta recente. O tipo de falha mais recorrente, CWE-79 (Cross-Site Scripting), aponta para fragilidades persistentes na camada de apresentação que exigem atenção continuada em práticas de desenvolvimento e validação de entrada.

CVE-2023-45182HIGHIBM i Access Client Solutions information disclosureEPSS 0.6%CVE-2026-84108HIGHIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.6%CVE-2023-32332MEDIUMIBM Maximo Application Suite and IBM Maximo Asset Management HTML injectionEPSS 0.6%CVE-2022-22344MEDIUMIBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to HTTP header injection, caused by improper validation of input byEPSS 0.6%CVE-2021-38984LOWIBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses weaker than expected cryptographic algorithms that could allow an attacker toEPSS 0.6%CVE-2026-80442CRITICALIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.6%CVE-2026-15065CRITICALVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.6%CVE-2021-38961MEDIUMIBM OPENBMC OP910 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thEPSS 0.6%CVE-2022-22427MEDIUMIBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript EPSS 0.6%CVE-2022-34352MEDIUMIBM QRadar information disclosureEPSS 0.6%CVE-2026-12946CRITICALRemote Code Execution in CUGA Component CodeAgentEPSS 0.6%CVE-2021-38876MEDIUMIBM i 7.2, 7.3, and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the WebEPSS 0.6%CVE-2022-43870MEDIUMIBM Spectrum Virtualize information disclosureEPSS 0.6%CVE-2026-8478HIGHLangflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handlingEPSS 0.6%CVE-2026-12628CRITICALHardcoded credential in the IBM Storage Protect Snapshot For Windows leads to unauthorized access to systemEPSS 0.6%CVE-2018-1521MEDIUMIBM Rational Team Concert 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users toEPSS 0.6%CVE-2018-1396MEDIUMIBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows usersEPSS 0.6%CVE-2019-4743MEDIUMIBM Financial Transaction Manager 3.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able toEPSS 0.6%CVE-2021-38985MEDIUMIBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not validate or incorrectly validates that theEPSS 0.6%CVE-2021-38972MEDIUMIBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not validate or incorrectly validates that theEPSS 0.6%