Vulnerabilidades em IBM

4.759 resultados
Análise Vexday

Com 4.716 CVEs catalogadas, o portfólio da IBM acumula um volume expressivo de vulnerabilidades, embora sua taxa de exploração ativa — 5 entradas no catálogo KEV da CISA, representando 0,11% do total — esteja abaixo da média geral do catálogo (0,45%), o que sugere menor aproveitamento ativo em comparação proporcional com outros vendors. A atenção deve se concentrar em CVE-2022-47986, cuja pontuação EPSS de 0,9997 indica probabilidade extremamente elevada de exploração ativa, tornando-a prioridade imediata de mitigação. As 92 CVEs críticas e 18 com PoC pública ampliam a superfície de risco concreto, especialmente considerando que 129 novas vulnerabilidades surgiram nos últimos 90 dias, indicando ritmo relevante de descoberta recente. O tipo de falha mais recorrente, CWE-79 (Cross-Site Scripting), aponta para fragilidades persistentes na camada de apresentação que exigem atenção continuada em práticas de desenvolvimento e validação de entrada.

CVE-2020-4254MEDIUMIBM Security Guardium Big Data Intelligence 1.0 (SonarG) uses weaker than expected cryptographic algorithms that could allow an attacker to EPSS 0.8%CVE-2020-4937MEDIUMIBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.2 uses weaker than expected cryptographic algorithms that could allow an EPSS 0.8%CVE-2020-4595MEDIUMIBM Security Guardium Insights 2.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensiEPSS 0.8%CVE-2020-4594MEDIUMIBM Security Guardium Insights 2.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensiEPSS 0.8%CVE-2020-4596MEDIUMIBM Security Guardium Insights 2.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensiEPSS 0.8%CVE-2020-4898MEDIUMIBM Emptoris Strategic Supply Management 10.1.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt hEPSS 0.8%CVE-2020-4778MEDIUMIBM Curam Social Program Management 7.0.9 and 7.0.10 uses MD5 algorithm for hashing token in a single instance which less safe than default EPSS 0.8%CVE-2023-40374MEDIUMIBM Db2 denial of serviceEPSS 0.8%CVE-2023-37404MEDIUMIBM Observability with Instana code executionEPSS 0.8%CVE-2023-38728MEDIUMIBM Db2 denial of serviceEPSS 0.8%CVE-2023-30987MEDIUMIBM Db2 denial of serviceEPSS 0.8%CVE-2023-38740MEDIUMIBM Db2 denial of serviceEPSS 0.8%CVE-2023-38720MEDIUMIBM Db2 denial of serviceEPSS 0.8%CVE-2019-4446MEDIUMIBM Maximo Asset Management 7.6 could allow an authenticated user perform actions they are not authorized to by modifying request parametersEPSS 0.8%CVE-2021-29853MEDIUMIBM Planning Analytics 2.0 could expose information that could be used to to create attacks by not validating the return values from some meEPSS 0.8%CVE-2017-1265LOWIBM Security Guardium 10.0, 10.0.1, 10.1, 10.1.2, 10.1.3, 10.1.4, and 10.5 does not validate, or incorrectly validates, a certificate. This EPSS 0.8%CVE-2021-39085MEDIUMIBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 is vulnerable to EPSS 0.8%CVE-2018-1455MEDIUMIBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 is vulnerable to cross-site request forgery which could allow an attacker EPSS 0.8%CVE-2021-39086MEDIUMIBM Sterling File Gateway 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 could allow a remote attacker to obtEPSS 0.8%CVE-2017-1500A Reflected Cross Site Scripting (XSS) vulnerability exists in the authorization function exposed by RESTful Web Api of IBM Worklight FramewEPSS 0.8%