Vulnerabilidades em IBM

4.716 resultados
Análise Vexday

Com 4.716 CVEs catalogadas, o portfólio da IBM acumula um volume expressivo de vulnerabilidades, embora sua taxa de exploração ativa — 5 entradas no catálogo KEV da CISA, representando 0,11% do total — esteja abaixo da média geral do catálogo (0,45%), o que sugere menor aproveitamento ativo em comparação proporcional com outros vendors. A atenção deve se concentrar em CVE-2022-47986, cuja pontuação EPSS de 0,9997 indica probabilidade extremamente elevada de exploração ativa, tornando-a prioridade imediata de mitigação. As 92 CVEs críticas e 18 com PoC pública ampliam a superfície de risco concreto, especialmente considerando que 129 novas vulnerabilidades surgiram nos últimos 90 dias, indicando ritmo relevante de descoberta recente. O tipo de falha mais recorrente, CWE-79 (Cross-Site Scripting), aponta para fragilidades persistentes na camada de apresentação que exigem atenção continuada em práticas de desenvolvimento e validação de entrada.

CVE-2020-4400HIGHIBM Verify Gateway (IVG) 1.0.0 and 1.0.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force accounEPSS 1.6%CVE-2020-4611HIGHIBM Data Risk Manager (iDNA) 2.0.6 could allow an authenticated user to bypass security and execute actions reserved for admins. IBM X-ForceEPSS 1.6%CVE-2017-1267IBM Security Guardium 10.0 and 10.1 processes patches, image backups and other updates without sufficiently verifying the origin and integriEPSS 1.6%CVE-2024-35133MEDIUMIBM Security Verify Access HTTP open redirectEPSS 1.6%CVE-2018-1495MEDIUMIBM FlashSystem V840 and V900 products could allow an authenticated attacker with specialized access to overwrite arbitrary files which coulEPSS 1.6%CVE-2020-4214HIGHIBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to arbitrary delete a directory caused by improper validation EPSS 1.6%CVE-2023-45184MEDIUMIBM i Access Client SolutionsEPSS 1.6%CVE-2019-4656MEDIUMIBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD is vulnerable to a denial of service attack that would allow an authEPSS 1.6%CVE-2020-4289MEDIUMIBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could allow a remote attacker to obtain sensitive informaEPSS 1.6%CVE-2019-4378MEDIUMIBM MQ 7.5.0.0 - 7.5.0.9, 7.1.0.0 - 7.1.0.9, 8.0.0.0 - 8.0.0.12, 9.0.0.0 - 9.0.0.6, 9.1.0.0 - 9.1.0.2, and 9.1.0 - 9.1.2 command server is vEPSS 1.6%CVE-2020-4435HIGHCertain IBM Aspera applications are vulnerable to arbitrary memory corruption based on the product configuration, which could allow an attacEPSS 1.6%CVE-2017-1162IBM QRadar 7.2 and 7.3 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the syEPSS 1.6%CVE-2016-9738IBM QRadar 7.2 and 7.3 does not require that users should have strong passwords by default, which makes it easier for attackers to compromisEPSS 1.6%CVE-2016-9984IBM Maximo Asset Management 7.5 and 7.6 could allow a remote authenticated attacker to execute arbitrary commands on the system as administrEPSS 1.6%CVE-2020-4175MEDIUMIBM Security Guardium Insights 2.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enableEPSS 1.6%CVE-2020-4979HIGHIBM QRadar SIEM 7.3 and 7.4 is vulnerable to insecure inter-deployment communication. An attacker that is able to comprimise or spoof traffiEPSS 1.6%CVE-2017-1197IBM BigFix Compliance (TEMA SUAv1 SCA SCM) uses an inadequate account lockout setting that could allow a remote attacker to brute force accoEPSS 1.6%CVE-2020-4580HIGHIBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sending a specially craftEPSS 1.6%CVE-2020-4581HIGHIBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sending a chunked transfeEPSS 1.6%CVE-2018-2015MEDIUMIBM API Connect 2018.1 and 2018.4.1.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to vEPSS 1.6%