Vulnerabilidades em IBM

5.644 resultados
Análise Vexday

Com 4.716 CVEs catalogadas, o portfólio da IBM acumula um volume expressivo de vulnerabilidades, embora sua taxa de exploração ativa — 5 entradas no catálogo KEV da CISA, representando 0,11% do total — esteja abaixo da média geral do catálogo (0,45%), o que sugere menor aproveitamento ativo em comparação proporcional com outros vendors. A atenção deve se concentrar em CVE-2022-47986, cuja pontuação EPSS de 0,9997 indica probabilidade extremamente elevada de exploração ativa, tornando-a prioridade imediata de mitigação. As 92 CVEs críticas e 18 com PoC pública ampliam a superfície de risco concreto, especialmente considerando que 129 novas vulnerabilidades surgiram nos últimos 90 dias, indicando ritmo relevante de descoberta recente. O tipo de falha mais recorrente, CWE-79 (Cross-Site Scripting), aponta para fragilidades persistentes na camada de apresentação que exigem atenção continuada em práticas de desenvolvimento e validação de entrada.

CVE-2016-2970—IBM Sametime 8.5 and 9.0 meetings server may provide detailed information in an error message that may provide details about the applicationEPSS 1.1%CVE-2021-29739LOWIBM Planning Analytics Local 2.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browserEPSS 1.1%CVE-2023-24958HIGHIBM TS7700 Management Interface command injectionEPSS 1.1%CVE-2022-22483MEDIUMIBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to an information disclosure in some scenarios due to unauEPSS 1.1%CVE-2021-29678HIGHIBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a user with DBADM authority toEPSS 1.1%CVE-2021-38919MEDIUMIBM QRadar SIEM 7.3, 7.4, and 7.5 in some senarios may reveal authorized service tokens to other QRadar users. IBM X-Force ID: 210021EPSS 1.1%CVE-2023-45178MEDIUMIBM Db2 denial of serviceEPSS 1.1%CVE-2019-6159CRITICALA stored cross-site scripting (XSS) vulnerability exists in various firmware versions of the legacy IBM System x IMM (IMM v1) embedded BasebEPSS 1.1%CVE-2018-1543MEDIUMIBM WebSphere MQ 8.0 and 9.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly validate the SEPSS 1.1%CVE-2023-46167MEDIUMIBM Db2 denial of serviceEPSS 1.1%CVE-2017-1786—IBM WebSphere MQ 8.0 through 8.0.0.8 and 9.0 through 9.0.4 under special circumstances could allow an authenticated user to consume all resoEPSS 1.1%CVE-2018-1413—IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the WEPSS 1.1%CVE-2023-38003HIGHIBM Db2 command executionEPSS 1.1%CVE-2020-4151MEDIUMIBM QRadar SIEM 7.3.0 through 7.3.3 could allow an authenticated attacker to perform unauthorized actions due to improper input validation. EPSS 1.1%CVE-2022-22323MEDIUMIBM Security Identity Manager (IBM Security Verify Password Synchronization Plug-in for Windows AD 10.x) is vulnerable to a denial of servicEPSS 1.1%CVE-2022-22312MEDIUMIBM Security Identity Manager (IBM Security Verify Password Synchronization Plug-in for Windows AD 10.x) is vulnerable to a denial of servicEPSS 1.1%CVE-2022-34160MEDIUMIBM CICS TX Standard and Advanced 11.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when vieweEPSS 1.1%CVE-2020-4901MEDIUMIBM Robotic Process Automation with Automation Anywhere 11.0 could allow an attacker on the network to obtain sensitive information or causeEPSS 1.1%CVE-2018-1423MEDIUMIBM Jazz Foundation products could disclose sensitive information to an authenticated attacker that could be used in further attacks againstEPSS 1.1%CVE-2023-40699HIGHIBM InfoSphere Information Server denial of serviceEPSS 1.1%