Vulnerabilidades em IBM

4.759 resultados
Análise Vexday

Com 4.716 CVEs catalogadas, o portfólio da IBM acumula um volume expressivo de vulnerabilidades, embora sua taxa de exploração ativa — 5 entradas no catálogo KEV da CISA, representando 0,11% do total — esteja abaixo da média geral do catálogo (0,45%), o que sugere menor aproveitamento ativo em comparação proporcional com outros vendors. A atenção deve se concentrar em CVE-2022-47986, cuja pontuação EPSS de 0,9997 indica probabilidade extremamente elevada de exploração ativa, tornando-a prioridade imediata de mitigação. As 92 CVEs críticas e 18 com PoC pública ampliam a superfície de risco concreto, especialmente considerando que 129 novas vulnerabilidades surgiram nos últimos 90 dias, indicando ritmo relevante de descoberta recente. O tipo de falha mais recorrente, CWE-79 (Cross-Site Scripting), aponta para fragilidades persistentes na camada de apresentação que exigem atenção continuada em práticas de desenvolvimento e validação de entrada.

CVE-2017-1255IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 uses weaker than expected cryptographic algorithms that could allow an attacker EPSS 1.1%CVE-2023-35893CRITICALIBM Security Guardium command executionEPSS 1.1%CVE-2012-3340MEDIUMIBM InfoSphere Guardium 8.0, 8.01, and 8.2 is vulnerable to XML external entity injection, caused by improper validation of user-supplied inEPSS 1.1%CVE-2018-1660MEDIUMIBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScEPSS 1.1%CVE-2018-1429MEDIUMIBM MQ Appliance 9.0.1, 9.0.2, 9.0.3, amd 9.0.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JaEPSS 1.1%CVE-2020-4953MEDIUMIBM Planning Analytics 2.0 could allow a remote authenticated attacker to obtain information about an organization's internal structure by eEPSS 1.1%CVE-2018-1380LOWIBM InfoSphere Master Data Management Collaboration Server 11.4, 11.5, and 11.6 could allow an authenticated user with CA level access to chEPSS 1.1%CVE-2020-4244MEDIUMIBM Security Identity Governance and Intelligence 5.2.6 could allow an unauthorized user to obtain sensitive information through user enumerEPSS 1.1%CVE-2019-4559MEDIUMIBM QRadar SIEM 7.3.0 through 7.3.3 discloses sensitive information to unauthorized users. The information can be used to mount further attaEPSS 1.1%CVE-2018-1682MEDIUMIBM Watson Studio Local 1.2.3 could disclose sensitive information over the network that an attacked could use in further attacks against thEPSS 1.1%CVE-2020-4186MEDIUMIBM Security Guardium 10.5, 10.6, and 11.1 could disclose sensitive information on the login page that could aid in further attacks against EPSS 1.1%CVE-2019-4537MEDIUMIBM WebSphere Service Registry and Repository 8.5 could allow a user to obtain sensitive version information that could be used in further aEPSS 1.1%CVE-2019-4550MEDIUMIBM Security Directory Server 6.4.0 is deployed with active debugging code that can create unintended entry points. IBM X-Force ID: 165952.EPSS 1.1%CVE-2020-4188MEDIUMIBM Security Guardium 10.6 and 11.1 may use insufficiently random numbers or values in a security context that depends on unpredictable numbEPSS 1.1%CVE-2020-4187MEDIUMIBM Security Guardium 11.1 could disclose sensitive information on the login page that could aid in further attacks against the system. IBM EPSS 1.1%CVE-2020-4342MEDIUMIBM Security Secret Server 10.7 could disclose sensitive information included in installation files to an unauthorized user. IBM X-Force ID:EPSS 1.1%CVE-2022-22355MEDIUMIBM MQ Appliance 9.2 CD and 9.2 LTS are vulnerable to a denial of service in the Login component of the application which could allow an attEPSS 1.1%CVE-2018-1369LOWIBM Security Guardium Big Data Intelligence (SonarG) 3.1 stores sensitive information in URL parameters. This may lead to information discloEPSS 1.1%CVE-2021-29856MEDIUMIBM Tivoli Netcool/OMNIbus_GUI 8.1.0 could allow an authenticated usre to cause a denial of service through the WebGUI Map Creation page. IBEPSS 1.1%CVE-2021-20423HIGHIBM Cloud Pak for Applications 4.3 could allow an authenticated user gain escalated privilesges due to improper application permissions. IBMEPSS 1.1%