Vulnerabilidades em IBM

5.644 resultados
Análise Vexday

Com 4.716 CVEs catalogadas, o portfólio da IBM acumula um volume expressivo de vulnerabilidades, embora sua taxa de exploração ativa — 5 entradas no catálogo KEV da CISA, representando 0,11% do total — esteja abaixo da média geral do catálogo (0,45%), o que sugere menor aproveitamento ativo em comparação proporcional com outros vendors. A atenção deve se concentrar em CVE-2022-47986, cuja pontuação EPSS de 0,9997 indica probabilidade extremamente elevada de exploração ativa, tornando-a prioridade imediata de mitigação. As 92 CVEs críticas e 18 com PoC pública ampliam a superfície de risco concreto, especialmente considerando que 129 novas vulnerabilidades surgiram nos últimos 90 dias, indicando ritmo relevante de descoberta recente. O tipo de falha mais recorrente, CWE-79 (Cross-Site Scripting), aponta para fragilidades persistentes na camada de apresentação que exigem atenção continuada em práticas de desenvolvimento e validação de entrada.

CVE-2019-4314MEDIUMIBM Security Guardium Big Data Intelligence (SonarG) 4.0 stores sensitive information in cleartext within a resource that might be accessiblEPSS 1.0%CVE-2022-22463MEDIUMIBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 is vulnerable to SQL injection. A remote attacker could senEPSS 1.0%CVE-2017-1366MEDIUMIBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 uses weaker than expected cryptographic algorithms that could allow aEPSS 1.0%CVE-2023-47702MEDIUMIBM Security Guardium Key Lifecycle Manager directory traversalEPSS 1.0%CVE-2026-8476CRITICALDisk Cache Deserialization Remote Code Execution VulnerabilityEPSS 1.0%CVE-2016-8950—IBM Emptoris Sourcing 9.5.x through 10.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrEPSS 1.0%CVE-2021-20508LOWIBM Security Secret Server up to 11.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message EPSS 1.0%CVE-2024-54181HIGHIBM WebSphere Automation command injectionEPSS 1.0%CVE-2012-3336MEDIUMIBM InfoSphere Guardium 8.0, 8.01, and 8.2 is vulnerable to SQL injection. A remote authenticated attacker could send specially-crafted SQL EPSS 1.0%CVE-2019-4387MEDIUMIBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.2.0 is vulnerable to SQL injection. A remote attacker could send specially-EPSS 1.0%CVE-2020-4647MEDIUMIBM Sterling File Gateway 2.2.0.0 through 2.2.6.5 and 6.0.0.0 through 6.0.3.2 is vulnerable to SQL injection. A remote attacker could send sEPSS 1.0%CVE-2019-4680MEDIUMIBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.2.2 is vulnerable to SQL injection. A remote attacker could send specially-EPSS 1.0%CVE-2018-1587MEDIUMIBM Rational Rhapsody Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 and IBM Rational Software Architect Design Manager 5.0 through EPSS 1.0%CVE-2017-1725—IBM Jazz Team Server affecting the following IBM Rational Products: Collaborative Lifecycle Management (CLM), Rational DOORS Next GenerationEPSS 1.0%CVE-2020-4850MEDIUMIBM Spectrum Scale 1.1.1.0 through 1.1.8.4 Transparent Cloud Tiering could allow a remote attacker to obtain sensitive information, caused bEPSS 1.0%CVE-2023-28513MEDIUMIBM MQ denial of serviceEPSS 1.0%CVE-2023-25684MEDIUMIBM Security Key Lifecycle Manager SQL injectionEPSS 1.0%CVE-2026-14512CRITICALIBM WebSphere Application Server is affected by an unsafe deserialization and exposure of sensitive informationEPSS 1.0%CVE-2017-1769—IBM Business Process Manager 8.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorEPSS 1.0%CVE-2021-38957LOWIBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 could disclose sensitive information due to hazardous input validation during QR code genEPSS 1.0%