Vulnerabilidades em IBM

4.716 resultados
Análise Vexday

Com 4.716 CVEs catalogadas, o portfólio da IBM acumula um volume expressivo de vulnerabilidades, embora sua taxa de exploração ativa — 5 entradas no catálogo KEV da CISA, representando 0,11% do total — esteja abaixo da média geral do catálogo (0,45%), o que sugere menor aproveitamento ativo em comparação proporcional com outros vendors. A atenção deve se concentrar em CVE-2022-47986, cuja pontuação EPSS de 0,9997 indica probabilidade extremamente elevada de exploração ativa, tornando-a prioridade imediata de mitigação. As 92 CVEs críticas e 18 com PoC pública ampliam a superfície de risco concreto, especialmente considerando que 129 novas vulnerabilidades surgiram nos últimos 90 dias, indicando ritmo relevante de descoberta recente. O tipo de falha mais recorrente, CWE-79 (Cross-Site Scripting), aponta para fragilidades persistentes na camada de apresentação que exigem atenção continuada em práticas de desenvolvimento e validação de entrada.

CVE-2021-29785MEDIUMIBM Security SOAR V42 and V43could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP StEPSS 1.3%CVE-2020-4166MEDIUMIBM Security Guardium Insights 2.0.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message iEPSS 1.3%CVE-2020-4532MEDIUMIBM Business Automation Workflow and IBM Business Process Manager (IBM Business Process Manager Express 8.5.5, 8.5.6, 8.5.7, and 8.6) could EPSS 1.3%CVE-2017-1705MEDIUMIBM Security Privileged Identity Manager 2.1.0 contains left-over, sensitive information in page comments. While this information is not visEPSS 1.3%CVE-2017-1557IBM WebSphere MQ 8.0 and 9.0 could allow an authenticated user with authority to send a specially crafted request that could cause a channelEPSS 1.3%CVE-2018-2008MEDIUMIBM TRIRIGA Application Platform 3.5.3 and 3.6.0 could disclose sensitive information to an authenticated user that could aid in further attEPSS 1.3%CVE-2020-4655MEDIUMIBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 is vulnerable to SQL injection. A remote atEPSS 1.3%CVE-2021-20480MEDIUMIBM WebSphere Application Server 7.0, 8.0, and 8.5 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted requeEPSS 1.3%CVE-2017-1214IBM iNotes 8.5 and 9.0 could allow a remote attacker to send a malformed email to a victim, that when opened could cause an information discEPSS 1.3%CVE-2020-4412MEDIUMThe Spectrum Scale 4.2.0.0 through 4.2.3.21 and 5.0.0.0 through 5.0.4.3 file system component is affected by a denial of service security vuEPSS 1.3%CVE-2020-4226MEDIUMIBM MobileFirst Platform Foundation 8.0.0.0 stores highly sensitive information in URL parameters. This may lead to information disclosure iEPSS 1.3%CVE-2020-4267MEDIUMIBM MQ and MQ Appliance 8.0, 9.1 LTS, and 9.1 CD could allow an authenticated user cause a denial of service due to a memory leak. IBM X-ForEPSS 1.3%CVE-2019-4752HIGHIBM Emptoris Spend Analysis and IBM Emptoris Strategic Supply Management Platform 10.1.0.x, 10.1.1.x, and 10.1.3.x is vulnerable to SQL injeEPSS 1.3%CVE-2022-31768MEDIUMIBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which EPSS 1.3%CVE-2017-3774A stack overflow vulnerability was discovered within the web administration service in Integrated Management Module 2 (IMM2) earlier than veEPSS 1.3%CVE-2020-4662MEDIUMIBM Event Streams 10.0.0 could allow an authenticated user to perform tasks to a schema due to improper authentication validation. IBM X-ForEPSS 1.3%CVE-2019-4538HIGHIBM Security Directory Server 6.4.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading EPSS 1.3%CVE-2020-4283MEDIUMIBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, and 1.0.4 contains hard-coded credentials, such as a password or cryptograEPSS 1.3%CVE-2017-1148IBM OpenPages GRC Platform 7.2 and 7.3 with OpenPages Loss Event Entry (LEE) application could allow a user to obtain sensitive information EPSS 1.3%CVE-2022-38389HIGHIBM Tivoli Workload Scheduler XML external entity injectionEPSS 1.3%