Vulnerabilidades em IBM

5.658 resultados
Análise Vexday

Com 4.716 CVEs catalogadas, o portfólio da IBM acumula um volume expressivo de vulnerabilidades, embora sua taxa de exploração ativa — 5 entradas no catálogo KEV da CISA, representando 0,11% do total — esteja abaixo da média geral do catálogo (0,45%), o que sugere menor aproveitamento ativo em comparação proporcional com outros vendors. A atenção deve se concentrar em CVE-2022-47986, cuja pontuação EPSS de 0,9997 indica probabilidade extremamente elevada de exploração ativa, tornando-a prioridade imediata de mitigação. As 92 CVEs críticas e 18 com PoC pública ampliam a superfície de risco concreto, especialmente considerando que 129 novas vulnerabilidades surgiram nos últimos 90 dias, indicando ritmo relevante de descoberta recente. O tipo de falha mais recorrente, CWE-79 (Cross-Site Scripting), aponta para fragilidades persistentes na camada de apresentação que exigem atenção continuada em práticas de desenvolvimento e validação de entrada.

CVE-2026-17444MEDIUMIBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEsEPSS 0.3%CVE-2026-17443MEDIUMIBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEsEPSS 0.3%CVE-2026-11937LOWSecurity vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify AccessEPSS 0.3%CVE-2022-41294MEDIUMIBM Robotic Process Automation 21.0.0, 21.0.1, 21.0.2, 21.0.3, and 21.0.4 is vulnerable to cross origin resource sharing using the bot api. EPSS 0.3%CVE-2017-1760—IBM WebSphere MQ 7.5, 8.0, and 9.0 could allow a local user to crash the queue manager agent thread and expose some sensitive information. IEPSS 0.3%CVE-2025-14806MEDIUMIBM Planning Analytics Information DisclosureEPSS 0.3%CVE-2020-4491MEDIUMIBM Spectrum Scale V4.2.0.0 through V4.2.3.22 and V5.0.0.0 through V5.0.5 could allow a local attacker to cause a denial of service by sendiEPSS 0.3%CVE-2026-17646HIGHIBM Financial Transaction Manager (FTM) is Impacted by Multiple VulnerabilitiesEPSS 0.3%CVE-2023-42027MEDIUMIBM CICS TX cross-site request forgeryEPSS 0.3%CVE-2020-4498MEDIUMIBM MQ Appliance 9.1 LTS and 9.1 CD could allow a local privileged user to obtain highly sensitve information due to inclusion of data withiEPSS 0.3%CVE-2022-22493LOWIBM WebSphere Automation for Cloud Pak for Watson AIOps 1.4.2 is vulnerable to cross-site request forgery, caused by improper cookie attribuEPSS 0.3%CVE-2025-1494MEDIUMIBM Cognos Command Center clickjackingEPSS 0.3%CVE-2020-4885MEDIUMIBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow a local user to access and change the configuration of DbEPSS 0.3%CVE-2026-81207HIGHDataStage on Cloud Pak for Data has several vulnerabilities due to open source softwareEPSS 0.3%CVE-2020-4787MEDIUMIBM QRadar SIEM 7.4.2 GA to 7.4.2 Patch 1, 7.4.0 to 7.4.1 Patch 1, and 7.3.0 to 7.3.3 Patch 5 is vulnerable to server side request forgery (EPSS 0.3%CVE-2024-47118MEDIUMIBM Db2 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted queryEPSS 0.3%CVE-2022-22506MEDIUMIBM Robotic Process Automation information disclosureEPSS 0.3%CVE-2020-4900MEDIUMIBM Business Automation Workflow 19.0.0.3 stores potentially sensitive information in log files that could be read by a local user. IBM X-FoEPSS 0.3%CVE-2022-22359MEDIUMIBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to cross-site request forgery which could allow an attEPSS 0.3%CVE-2025-36104MEDIUMIBM Storage Scale information disclosureEPSS 0.3%