Vulnerabilidades em IBM

5.658 resultados
Análise Vexday

Com 4.716 CVEs catalogadas, o portfólio da IBM acumula um volume expressivo de vulnerabilidades, embora sua taxa de exploração ativa — 5 entradas no catálogo KEV da CISA, representando 0,11% do total — esteja abaixo da média geral do catálogo (0,45%), o que sugere menor aproveitamento ativo em comparação proporcional com outros vendors. A atenção deve se concentrar em CVE-2022-47986, cuja pontuação EPSS de 0,9997 indica probabilidade extremamente elevada de exploração ativa, tornando-a prioridade imediata de mitigação. As 92 CVEs críticas e 18 com PoC pública ampliam a superfície de risco concreto, especialmente considerando que 129 novas vulnerabilidades surgiram nos últimos 90 dias, indicando ritmo relevante de descoberta recente. O tipo de falha mais recorrente, CWE-79 (Cross-Site Scripting), aponta para fragilidades persistentes na camada de apresentação que exigem atenção continuada em práticas de desenvolvimento e validação de entrada.

CVE-2026-18716HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.3%CVE-2018-1368—IBM Security Guardium Database Activity Monitor 9.0, 9.1, and 9.5 could allow a local user with low privileges to view report pages and perfEPSS 0.3%CVE-2020-4528MEDIUMIBM MQ Appliance (IBM DataPower Gateway 10.0.0.0 and 2018.4.1.0 through 2018.4.1.12) could allow a local user, under special conditions, to EPSS 0.3%CVE-2025-36087HIGHIBM Security Verify Access hard coded credentialsEPSS 0.3%CVE-2018-1550MEDIUMIBM Spectrum Protect 7.1 and 8.1 could allow a local user to corrupt or delete highly sensitive information that would cause a denial of serEPSS 0.3%CVE-2026-9736MEDIUMVulnerabilities exists in IBM Netezza SoftwareEPSS 0.3%CVE-2026-18076MEDIUMIBM i is Affected By Multiple Vulnerabilities in Debug ServerEPSS 0.3%CVE-2023-28523HIGHIBM Informix Dynamic Server buffer overflowEPSS 0.3%CVE-2021-38990HIGHIBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the mount command which could lead to cEPSS 0.3%CVE-2026-18078MEDIUMIBM i is Affected By Denial of Service Vulnerability in Save Restore []EPSS 0.3%CVE-2026-18527CRITICALIBM Application Runtime Expert (ARE) for IBM i is vulnerable to a user gaining elevated privileges and sensitive information [, ].EPSS 0.3%CVE-2025-36015MEDIUMIBM Controller Denial of ServiceEPSS 0.3%CVE-2023-50941MEDIUMIBM PowerSC session fixationEPSS 0.3%CVE-2025-36140MEDIUMIBM watsonx.data Denial of ServiceEPSS 0.3%CVE-2024-47109MEDIUMIBM Sterling File Gateway information disclosureEPSS 0.3%CVE-2019-4394LOWIBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 contain APIs that could be used by a local user to send email. IBM X-ForcEPSS 0.3%CVE-2026-17074LOWIBM i is Affected By Multiple Vulnerabilities in DRDA / DDMEPSS 0.3%CVE-2026-2484MEDIUMIBM InfoSphere Information Server Information DisclosureEPSS 0.3%CVE-2024-51456MEDIUMIBM Robotic Process Automation information disclosureEPSS 0.3%CVE-2024-25053MEDIUMIBM Cognos Analytics improper certificate validationEPSS 0.3%