Vulnerabilidades em IBM

5.644 resultados
Análise Vexday

Com 4.716 CVEs catalogadas, o portfólio da IBM acumula um volume expressivo de vulnerabilidades, embora sua taxa de exploração ativa — 5 entradas no catálogo KEV da CISA, representando 0,11% do total — esteja abaixo da média geral do catálogo (0,45%), o que sugere menor aproveitamento ativo em comparação proporcional com outros vendors. A atenção deve se concentrar em CVE-2022-47986, cuja pontuação EPSS de 0,9997 indica probabilidade extremamente elevada de exploração ativa, tornando-a prioridade imediata de mitigação. As 92 CVEs críticas e 18 com PoC pública ampliam a superfície de risco concreto, especialmente considerando que 129 novas vulnerabilidades surgiram nos últimos 90 dias, indicando ritmo relevante de descoberta recente. O tipo de falha mais recorrente, CWE-79 (Cross-Site Scripting), aponta para fragilidades persistentes na camada de apresentação que exigem atenção continuada em práticas de desenvolvimento e validação de entrada.

CVE-2020-4186MEDIUMIBM Security Guardium 10.5, 10.6, and 11.1 could disclose sensitive information on the login page that could aid in further attacks against EPSS 1.1%CVE-2018-1682MEDIUMIBM Watson Studio Local 1.2.3 could disclose sensitive information over the network that an attacked could use in further attacks against thEPSS 1.1%CVE-2019-4547MEDIUMIBM Security Directory Server 6.4.0 generates an error message that includes sensitive information about its environment, users, or associatEPSS 1.1%CVE-2019-4550MEDIUMIBM Security Directory Server 6.4.0 is deployed with active debugging code that can create unintended entry points. IBM X-Force ID: 165952.EPSS 1.1%CVE-2019-4559MEDIUMIBM QRadar SIEM 7.3.0 through 7.3.3 discloses sensitive information to unauthorized users. The information can be used to mount further attaEPSS 1.1%CVE-2019-4537MEDIUMIBM WebSphere Service Registry and Repository 8.5 could allow a user to obtain sensitive version information that could be used in further aEPSS 1.1%CVE-2021-20423HIGHIBM Cloud Pak for Applications 4.3 could allow an authenticated user gain escalated privilesges due to improper application permissions. IBMEPSS 1.1%CVE-2021-29752MEDIUMIBM Db2 11.2 and 11.5 contains an information disclosure vulnerability, exposing remote storage credentials to privileged users under specifEPSS 1.1%CVE-2021-38960MEDIUMIBM OPENBMC OP920, OP930, and OP940 could allow an unauthenticated user to obtain sensitive information. IBM X-Force ID: 212047.EPSS 1.1%CVE-2023-42004HIGHIBM Security Guardium CSV injectionEPSS 1.1%CVE-2017-1711—IBM iNotes 8.5 and 9.0 SUService can be misguided into running malicious code from a DLL masquerading as a windows DLL in the temp directoryEPSS 1.1%CVE-2018-1774HIGHIBM API Connect 5.0.0.0, 5.0.8.4, 2018.1 and 2018.3.6 is vulnerable to CSV injection via the developer portal and analytics that could contaEPSS 1.1%CVE-2017-1255—IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 uses weaker than expected cryptographic algorithms that could allow an attacker EPSS 1.1%CVE-2018-1600HIGHIBM BigFix Platform 9.2 and 9.5 transmits sensitive or security-critical data in clear text in a communication channel that can be sniffed bEPSS 1.1%CVE-2017-1257—IBM Security Guardium 10.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on thEPSS 1.1%CVE-2019-4297MEDIUMIBM Robotic Process Automation with Automation Anywhere 11 could allow a remote authenticated attacker to conduct an LDAP injection. By usinEPSS 1.1%CVE-2017-1374—Sensitive data can be exposed in the IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 that can lead to an attacker gaining unauthorized acEPSS 1.1%CVE-2021-38923HIGHIBM PowerVM Hypervisor FW1010 could allow a privileged user to gain access to another VM due to assigning duplicate WWPNs. IBM X-Force ID: 2EPSS 1.1%CVE-2022-22473LOWIBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information caused by improper hanEPSS 1.1%CVE-2019-4560MEDIUMIBM MQ and IBM MQ Appliance 9.1 CD, 9.1 LTS, 9.0 LTS, and 8.0 is vulnerable to a denial of service attack caused by channels processing poorEPSS 1.1%