Vulnerabilidades em IBM

5.658 resultados
Análise Vexday

Com 4.716 CVEs catalogadas, o portfólio da IBM acumula um volume expressivo de vulnerabilidades, embora sua taxa de exploração ativa — 5 entradas no catálogo KEV da CISA, representando 0,11% do total — esteja abaixo da média geral do catálogo (0,45%), o que sugere menor aproveitamento ativo em comparação proporcional com outros vendors. A atenção deve se concentrar em CVE-2022-47986, cuja pontuação EPSS de 0,9997 indica probabilidade extremamente elevada de exploração ativa, tornando-a prioridade imediata de mitigação. As 92 CVEs críticas e 18 com PoC pública ampliam a superfície de risco concreto, especialmente considerando que 129 novas vulnerabilidades surgiram nos últimos 90 dias, indicando ritmo relevante de descoberta recente. O tipo de falha mais recorrente, CWE-79 (Cross-Site Scripting), aponta para fragilidades persistentes na camada de apresentação que exigem atenção continuada em práticas de desenvolvimento e validação de entrada.

CVE-2026-18137HIGHIBM Financial Transaction Manager (FTM) is Impacted by Multiple VulnerabilitiesEPSS 0.3%CVE-2023-26286HIGHIBM AIX privilege escalationEPSS 0.3%CVE-2023-23473MEDIUMIBM InfoSphere Information Server cross-site request forgeryEPSS 0.3%CVE-2026-18511HIGHIBM i is Affected By Multiple Vulnerabilities in Java Secure Sockets ExtensionEPSS 0.3%CVE-2025-36365MEDIUMIBM Db2 Privilege EscalationEPSS 0.3%CVE-2024-49783MEDIUMIBM OpenPages with Watson information disclosureEPSS 0.3%CVE-2024-31874MEDIUMIBM Security Verify Access Appliance denial of serviceEPSS 0.3%CVE-2026-11928CRITICALSecurity vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify AccessEPSS 0.3%CVE-2025-13691HIGHDataStage on Cloud Pak for Data is vulnerable to sensitive information leaks due to HTTP processingEPSS 0.3%CVE-2020-4609HIGHIBM Security Sevret Server (IBM Security Verify Privilege Manager 10.8.2) is vulnerable to a buffer overflow, caused by improper bounds checEPSS 0.3%CVE-2026-13442HIGHLangflow is affected by NET Misconfiguration: Use of Impersonation due to multiple unauthenticated and insufficiently authorized API endpointsEPSS 0.3%CVE-2022-35286LOWIBM Security Verify Information Queue 10.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious EPSS 0.3%CVE-2023-47718MEDIUMIBM Maximo Asset Management cross-site request forgeryEPSS 0.3%CVE-2024-56464LOWIBM QRadar SIEM is affected by an information disclosure vulnerabilityEPSS 0.3%CVE-2026-1561MEDIUMIBM WebSphere Application Server Liberty Server-Side Request ForgeryEPSS 0.3%CVE-2017-1261—IBM Security Guardium 10.0 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 124736.EPSS 0.3%CVE-2019-4588HIGHIBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to execute arbitrEPSS 0.3%CVE-2026-12756HIGHMultiple secuirty vulnerabilies addressed with IBM Business Automation Workflow August 2026EPSS 0.3%CVE-2017-1284—IBM WebSphere MQ 9.0.1 and 9.0.2 could allow a local user with ability to run or enable trace, to obtain sensitive information from WebSpherEPSS 0.3%CVE-2026-17621MEDIUMLangflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base componentsEPSS 0.3%