Vulnerabilidades em IBM

5.652 resultados
Análise Vexday

Com 4.716 CVEs catalogadas, o portfólio da IBM acumula um volume expressivo de vulnerabilidades, embora sua taxa de exploração ativa — 5 entradas no catálogo KEV da CISA, representando 0,11% do total — esteja abaixo da média geral do catálogo (0,45%), o que sugere menor aproveitamento ativo em comparação proporcional com outros vendors. A atenção deve se concentrar em CVE-2022-47986, cuja pontuação EPSS de 0,9997 indica probabilidade extremamente elevada de exploração ativa, tornando-a prioridade imediata de mitigação. As 92 CVEs críticas e 18 com PoC pública ampliam a superfície de risco concreto, especialmente considerando que 129 novas vulnerabilidades surgiram nos últimos 90 dias, indicando ritmo relevante de descoberta recente. O tipo de falha mais recorrente, CWE-79 (Cross-Site Scripting), aponta para fragilidades persistentes na camada de apresentação que exigem atenção continuada em práticas de desenvolvimento e validação de entrada.

CVE-2024-41742HIGHIBM TXSeries for Multiplatforms denial of serviceEPSS 0.7%CVE-2020-4319LOWIBM MQ, IBM MQ Appliance, and IBM MQ for HPE NonStop 8.0, 9.1 LTS, and 9.1 CD could allow under special circumstances, an authenticated userEPSS 0.7%CVE-2019-4426MEDIUMThe Case Builder component shipped with 18.0.0.1 through 19.0.0.2 and IBM Case Manager 5.1.1 through 5.3 is vulnerable to cross-site scriptiEPSS 0.7%CVE-2020-4564MEDIUMIBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.1 and IBM Sterling File Gateway 2.2.0.0 through 6.0.3.1 are vulnerable toEPSS 0.7%CVE-2022-22315MEDIUMIBM UrbanCode Deploy (UCD) 7.2.2.1 could allow an authenticated user with special permissions to obtain elevated privileges due to improper EPSS 0.7%CVE-2020-4903MEDIUMIBM API Connect V10 and V2018 could allow an attacker who has intercepted a registration invitation link to impersonate the registered user EPSS 0.7%CVE-2026-17110HIGHIBM i is Affected By Multiple Vulnerabilities in SQLEPSS 0.7%CVE-2017-1183—IBM Tivoli Monitoring Portal v6 could allow a local (network adjacent) attacker to modify SQL commands to the Portal Server, when default clEPSS 0.7%CVE-2021-20432MEDIUMIBM Spectrum Protect Plus 10.1.0 through 10.1.7 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileEPSS 0.7%CVE-2023-26284HIGHIBM MQ Certified Container improper access controlsEPSS 0.7%CVE-2026-7755HIGHMCP Server Configuration Validator Bypass via File Upload APIEPSS 0.7%CVE-2020-5026MEDIUMIBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.2.0 through 3.2.7 could allow a remote attacker to obtain sensitEPSS 0.7%CVE-2026-16860CRITICALIBM i is Affected By Remote Code Execution Vulnerability []EPSS 0.7%CVE-2023-33835MEDIUMIBM Security Verify Information Queue information disclosureEPSS 0.7%CVE-2026-16674HIGHIBM i is Affected By Multiple Vulnerabilities in WebSphere Application Server LibertyEPSS 0.7%CVE-2026-18669HIGHIBM i is Affected By A Privilege Escalation Vulnerability []EPSS 0.7%CVE-2022-22368MEDIUMIBM Spectrum Scale 5.1.0 through 5.1.3.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sEPSS 0.7%CVE-2021-29754MEDIUMIBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a privilege escalation vulnerability when using the SAML Web InbounEPSS 0.7%CVE-2020-4967LOWIBM Cloud Pak for Security (CP4S) 1.3.0.1 could disclose sensitive information through HTTP headers which could be used in further attacks aEPSS 0.7%CVE-2022-43863MEDIUMIBM QRadar SIEM privilege escalationEPSS 0.7%