Vulnerabilidades em IBM

5.652 resultados
Análise Vexday

Com 4.716 CVEs catalogadas, o portfólio da IBM acumula um volume expressivo de vulnerabilidades, embora sua taxa de exploração ativa — 5 entradas no catálogo KEV da CISA, representando 0,11% do total — esteja abaixo da média geral do catálogo (0,45%), o que sugere menor aproveitamento ativo em comparação proporcional com outros vendors. A atenção deve se concentrar em CVE-2022-47986, cuja pontuação EPSS de 0,9997 indica probabilidade extremamente elevada de exploração ativa, tornando-a prioridade imediata de mitigação. As 92 CVEs críticas e 18 com PoC pública ampliam a superfície de risco concreto, especialmente considerando que 129 novas vulnerabilidades surgiram nos últimos 90 dias, indicando ritmo relevante de descoberta recente. O tipo de falha mais recorrente, CWE-79 (Cross-Site Scripting), aponta para fragilidades persistentes na camada de apresentação que exigem atenção continuada em práticas de desenvolvimento e validação de entrada.

CVE-2019-4631HIGHIBM Security Secret Server 10.7 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a viEPSS 0.8%CVE-2020-4595MEDIUMIBM Security Guardium Insights 2.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensiEPSS 0.8%CVE-2020-4594MEDIUMIBM Security Guardium Insights 2.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensiEPSS 0.8%CVE-2020-4898MEDIUMIBM Emptoris Strategic Supply Management 10.1.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt hEPSS 0.8%CVE-2020-4596MEDIUMIBM Security Guardium Insights 2.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensiEPSS 0.8%CVE-2023-38740MEDIUMIBM Db2 denial of serviceEPSS 0.8%CVE-2023-30987MEDIUMIBM Db2 denial of serviceEPSS 0.8%CVE-2023-37404MEDIUMIBM Observability with Instana code executionEPSS 0.8%CVE-2023-40374MEDIUMIBM Db2 denial of serviceEPSS 0.8%CVE-2023-38720MEDIUMIBM Db2 denial of serviceEPSS 0.8%CVE-2023-38728MEDIUMIBM Db2 denial of serviceEPSS 0.8%CVE-2019-4446MEDIUMIBM Maximo Asset Management 7.6 could allow an authenticated user perform actions they are not authorized to by modifying request parametersEPSS 0.8%CVE-2021-29853MEDIUMIBM Planning Analytics 2.0 could expose information that could be used to to create attacks by not validating the return values from some meEPSS 0.8%CVE-2018-1455MEDIUMIBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 is vulnerable to cross-site request forgery which could allow an attacker EPSS 0.8%CVE-2026-11595MEDIUMIBM WebSphere Application Server is affected by a Path Traversal vulnerabilityEPSS 0.8%CVE-2017-1265LOWIBM Security Guardium 10.0, 10.0.1, 10.1, 10.1.2, 10.1.3, 10.1.4, and 10.5 does not validate, or incorrectly validates, a certificate. This EPSS 0.8%CVE-2017-1500—A Reflected Cross Site Scripting (XSS) vulnerability exists in the authorization function exposed by RESTful Web Api of IBM Worklight FramewEPSS 0.8%CVE-2021-20405LOWIBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a user to perform unauthorized activities due to improper encoding of outpEPSS 0.8%CVE-2017-1549—IBM Sterling File Gateway 2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in tEPSS 0.8%CVE-2021-39040MEDIUMIBM Planning Analytics Workspace 2.0 could be vulnerable to malicious file upload by not validating the file types or sizes. Attackers can mEPSS 0.8%