Vulnerabilidades em IBM

5.625 resultados
Análise Vexday

Com 4.716 CVEs catalogadas, o portfólio da IBM acumula um volume expressivo de vulnerabilidades, embora sua taxa de exploração ativa — 5 entradas no catálogo KEV da CISA, representando 0,11% do total — esteja abaixo da média geral do catálogo (0,45%), o que sugere menor aproveitamento ativo em comparação proporcional com outros vendors. A atenção deve se concentrar em CVE-2022-47986, cuja pontuação EPSS de 0,9997 indica probabilidade extremamente elevada de exploração ativa, tornando-a prioridade imediata de mitigação. As 92 CVEs críticas e 18 com PoC pública ampliam a superfície de risco concreto, especialmente considerando que 129 novas vulnerabilidades surgiram nos últimos 90 dias, indicando ritmo relevante de descoberta recente. O tipo de falha mais recorrente, CWE-79 (Cross-Site Scripting), aponta para fragilidades persistentes na camada de apresentação que exigem atenção continuada em práticas de desenvolvimento e validação de entrada.

CVE-2020-4236MEDIUMIBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 could allow an authenticated user to cause a denial of service due to improper content paEPSS 1.4%CVE-2019-4036HIGHIBM Security Access Manager Appliance could allow unauthenticated attacker to cause a denial of service in the reverse proxy component. IBM EPSS 1.4%CVE-2018-1647HIGHIBM QRadar Incident Forensics 7.2 and 7.3 does not properly restrict the size or amount of resources requested which could allow an unauthenEPSS 1.4%CVE-2021-20470MEDIUMIBM Cognos Analytics 11.1.7 and 11.2.0 does not require that users should have strong passwords by default, which makes it easier for attackEPSS 1.4%CVE-2023-25926MEDIUMIBM Security Guardium Key Lifecycle Manager XML external entity injectionEPSS 1.4%CVE-2021-20584MEDIUMIBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow a remote attacker to upload arbitrary files, caused by improper access controlEPSS 1.4%CVE-2020-4588HIGHIBM i2 iBase 8.9.13 could allow an attacker to upload arbitrary executable files which, when executed by an unsuspecting victim could resultEPSS 1.4%CVE-2017-1460IBM i OSPF 6.1, 7.1, 7.2, and 7.3 is vulnerable when a rogue router spoofs its origin. Routing tables are affected by a missing LSA, which mEPSS 1.4%CVE-2021-38981MEDIUMIBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information when a detailed techEPSS 1.4%CVE-2023-30445HIGHIBM Db2 denial of serviceEPSS 1.4%CVE-2023-30449HIGHIBM Db2 denial of serviceEPSS 1.4%CVE-2021-29777MEDIUMIBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5, under specific circumstance of a table beEPSS 1.4%CVE-2019-4651MEDIUMIBM Jazz Reporting Service (JRS) 6.0.6.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, whicEPSS 1.4%CVE-2018-1421HIGHIBM WebSphere DataPower Appliances 7.1, 7.2, 7.5, 7.5.1, 7.5.2, and 7.6 is vulnerable to a XML External Entity Injection (XXE) attack when pEPSS 1.4%CVE-2022-22486CRITICALIBM Tivoli Workload Scheduler XML external entity injectionEPSS 1.4%CVE-2019-4224MEDIUMIBM PureApplication System 2.2.3.0 through 2.2.5.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statemEPSS 1.4%CVE-2020-4209MEDIUMIBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to traverse directories on the system. An attacker could send EPSS 1.4%CVE-2022-31768MEDIUMIBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which EPSS 1.4%CVE-2019-4194MEDIUMIBM Jazz for Service Management 1.1.3, 1.1.3.1, and 1.1.3.2 is missing function level access control that could allow a user to delete authoEPSS 1.4%CVE-2022-32752HIGHIBM Security Directory Suite VA command executionEPSS 1.4%