Записи IBM
8 833 опубликованных записей вендора ibm.
Профиль для исследователя
- Попали в KEV
- 10 · 0,1 %
- С эксплойтом
- 60 · 0,7 %
- Pre-auth RCE
- 456
- С записью об исправлении
- 1,9 %
- Медиана: публикация → KEV
- 1193 дн.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1 548
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor711
- CWE-264 Permissions, Privileges, and Access Controls336
- CWE-20 Improper Input Validation328
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer264
- CWE-352 Cross-Site Request Forgery (CSRF)227
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
8 833 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2014-6271Готовый эксплойт | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attacgnu · bash · CWE-78 | Критическая9,8 | KEV | 100,0 % | 24 сент. 2014 г. |
99Срочно | CVE-2017-5638Готовый эксплойт | The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mesapache · struts · CWE-755 | Критическая9,8 | KEV | 100,0 % | 10 мар. 2017 г. |
99Срочно | CVE-2022-47986Готовый эксплойт | IBM Aspera Faspex code executionibm · aspera faspex · CWE-502 | Критическая9,8 | KEV | 100,0 % | 17 февр. 2023 г. |
99Срочно | CVE-2014-7169Готовый эксплойт | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variablgnu · bash · CWE-78 | Критическая9,8 | KEV | 99,9 % | 24 сент. 2014 г. |
98Срочно | CVE-2015-7450Готовый эксплойт | Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products alloibm · sterling b2b integrator · CWE-502 | Критическая9,8 | KEV | 97,8 % | 2 янв. 2016 г. |
95Срочно | CVE-2019-4716Готовый эксплойт | IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "adminibm · planning analytics · CWE-94 | Критическая9,8 | KEV | 86,4 % | 18 дек. 2019 г. |
90Срочно | CVE-2020-4427Готовый эксплойт | IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configibm · data risk manager · CWE-287 | Критическая9,8 | KEV | 70,0 % | 7 мая 2020 г. |
85Срочно | CVE-2020-4428Готовый эксплойт | IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the systemibm · data risk manager · CWE-78 | Критическая9,1 | KEV | 61,7 % | 7 мая 2020 г. |
68На этой неделе | CVE-2001-0797Готовый эксплойт | Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large numbesgi · irix | Критическая10,0 | — | 94,7 % | 12 дек. 2001 г. |
68На этой неделе | CVE-2015-0235Готовый эксплойт | Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-depengnu · glibc · CWE-787 | Критическая10,0 | — | 94,6 % | 28 янв. 2015 г. |
68На этой неделе | CVE-2010-0425Готовый эксплойт | modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, wapache · http server | Критическая10,0 | — | 94,2 % | 5 мар. 2010 г. |
68На этой неделе | CVE-2020-4430Готовый эксплойт | IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories on the system.ibm · data risk manager · CWE-22 | Средняя4,3 | KEV | 68,5 % | 7 мая 2020 г. |
63На этой неделе | CVE-2019-4279Готовый эксплойт | IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted ibm · websphere application server · CWE-502 | Критическая9,8 | — | 79,9 % | 17 мая 2019 г. |
63На этой неделе | CVE-2007-4880Готовый эксплойт | Buffer overflow in the Client Acceptor Daemon (CAD), dsmcad.exe, in certain IBM Tivoli Storage Manager (TSM) clients 5.1 before 5.1.8.1, 5.2ibm · tivoli storage manager client · CWE-119 | Критическая10,0 | — | 75,9 % | 27 сент. 2007 г. |
62На этой неделе | CVE-2024-22319Proof of concept | IBM Operational Decision Manager JDNI injectionibm · operational decision manager · CWE-74 | Критическая9,8 | — | 76,4 % | 1 февр. 2024 г. |
62На этой неделе | CVE-2017-1092Готовый эксплойт | IBM Informix Open Admin Tool 11.5, 11.7, and 12.1 could allow an unauthorized user to execute arbitrary code as system admin on Windows servibm · informix open admin tool | Критическая9,8 | — | 75,8 % | 22 мая 2017 г. |
61На этой неделе | CVE-2020-4429Готовый эксплойт | IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrative account.ibm · data risk manager · CWE-798 | Критическая9,8 | — | 72,0 % | 7 мая 2020 г. |
61На этой неделе | CVE-2008-4828Готовый эксплойт | Multiple stack-based buffer overflows in dsmagent.exe in the Remote Agent Service in the IBM Tivoli Storage Manager (TSM) client 5.1.0.0 thribm · tivoli storage manager client · CWE-119 | Критическая10,0 | — | 71,5 % | 5 мая 2009 г. |
60На этой неделе | CVE-2020-4211Эксплойта нет | IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system.ibm · spectrum protect · CWE-78 | Критическая9,8 | — | 71,1 % | 24 февр. 2020 г. |
60На этой неделе | CVE-2003-0694Готовый эксплойт | The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated usingsendmail · advanced message server | Критическая10,0 | — | 66,2 % | 6 окт. 2003 г. |
59В плане | CVE-2008-2240Готовый эксплойт | Stack-based buffer overflow in the Web Server service in IBM Lotus Domino before 7.0.3 FP1, and 8.x before 8.0.1, allows remote attackers toibm · lotus domino · CWE-119 | Критическая10,0 | — | 64,8 % | 22 мая 2008 г. |
59В плане | CVE-2009-3699Готовый эксплойт | Stack-based buffer overflow in libcsa.a (aka the calendar daemon library) in IBM AIX 5.x through 5.3.10 and 6.x through 6.1.3, and VIOS 2.1 ibm · vios · CWE-119 | Критическая10,0 | — | 62,3 % | 15 окт. 2009 г. |
58В плане | CVE-2007-1675Proof of concept | Buffer overflow in the CRAM-MD5 authentication mechanism in the IMAP server (nimap.exe) in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.ibm · lotus domino | Критическая10,0 | — | 61,2 % | 28 мар. 2007 г. |
58В плане | CVE-2007-1868Готовый эксплойт | The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 does not properly handle multipart/form-daibm · tivoli provisioning manager os deployment | Критическая10,0 | — | 59,3 % | 4 апр. 2007 г. |
57В плане | CVE-2020-4280Эксплойта нет | IBM QRadar SIEM 7.3 and 7.4 could allow a remote attacker to execute arbitrary commands on the system, caused by insecure deserialization ofibm · qradar security information and event manager · CWE-502 | Высокая8,8 | — | 73,5 % | 8 окт. 2020 г. |
- CVE-2014-627199Срочно
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %gnu · bash24 сент. 2014 г.
- CVE-2017-563899Срочно
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mes
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %apache · struts10 мар. 2017 г.
- CVE-2022-4798699Срочно
IBM Aspera Faspex code execution
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %ibm · aspera faspex17 февр. 2023 г.
- CVE-2014-716999Срочно
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %gnu · bash24 сент. 2014 г.
- CVE-2015-745098Срочно
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allo
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 98 %ibm · sterling b2b integrator2 янв. 2016 г.
- CVE-2019-471695Срочно
IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 86 %ibm · planning analytics18 дек. 2019 г.
- CVE-2020-442790Срочно
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when config
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 70 %ibm · data risk manager7 мая 2020 г.
- CVE-2020-442885Срочно
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system
КритическаяCVSS 9,1KEVГотовый эксплойтEPSS 62 %ibm · data risk manager7 мая 2020 г.
- CVE-2001-079768На этой неделе
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large numbe
КритическаяCVSS 10,0Готовый эксплойтEPSS 95 %sgi · irix12 дек. 2001 г.
- CVE-2015-023568На этой неделе
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-depen
КритическаяCVSS 10,0Готовый эксплойтEPSS 95 %gnu · glibc28 янв. 2015 г.
- CVE-2010-042568На этой неделе
modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, w
КритическаяCVSS 10,0Готовый эксплойтEPSS 94 %apache · http server5 мар. 2010 г.
- CVE-2020-443068На этой неделе
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories on the system.
СредняяCVSS 4,3KEVГотовый эксплойтEPSS 69 %ibm · data risk manager7 мая 2020 г.
- CVE-2019-427963На этой неделе
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted
КритическаяCVSS 9,8Готовый эксплойтEPSS 80 %ibm · websphere application server17 мая 2019 г.
- CVE-2007-488063На этой неделе
Buffer overflow in the Client Acceptor Daemon (CAD), dsmcad.exe, in certain IBM Tivoli Storage Manager (TSM) clients 5.1 before 5.1.8.1, 5.2
КритическаяCVSS 10,0Готовый эксплойтEPSS 76 %ibm · tivoli storage manager client27 сент. 2007 г.
- CVE-2024-2231962На этой неделе
IBM Operational Decision Manager JDNI injection
КритическаяCVSS 9,8Proof of conceptEPSS 76 %ibm · operational decision manager1 февр. 2024 г.
- CVE-2017-109262На этой неделе
IBM Informix Open Admin Tool 11.5, 11.7, and 12.1 could allow an unauthorized user to execute arbitrary code as system admin on Windows serv
КритическаяCVSS 9,8Готовый эксплойтEPSS 76 %ibm · informix open admin tool22 мая 2017 г.
- CVE-2020-442961На этой неделе
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrative account.
КритическаяCVSS 9,8Готовый эксплойтEPSS 72 %ibm · data risk manager7 мая 2020 г.
- CVE-2008-482861На этой неделе
Multiple stack-based buffer overflows in dsmagent.exe in the Remote Agent Service in the IBM Tivoli Storage Manager (TSM) client 5.1.0.0 thr
КритическаяCVSS 10,0Готовый эксплойтEPSS 71 %ibm · tivoli storage manager client5 мая 2009 г.
- CVE-2020-421160На этой неделе
IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system.
КритическаяCVSS 9,8Эксплойта нетEPSS 71 %ibm · spectrum protect24 февр. 2020 г.
- CVE-2003-069460На этой неделе
The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using
КритическаяCVSS 10,0Готовый эксплойтEPSS 66 %sendmail · advanced message server6 окт. 2003 г.
- CVE-2008-224059В плане
Stack-based buffer overflow in the Web Server service in IBM Lotus Domino before 7.0.3 FP1, and 8.x before 8.0.1, allows remote attackers to
КритическаяCVSS 10,0Готовый эксплойтEPSS 65 %ibm · lotus domino22 мая 2008 г.
- CVE-2009-369959В плане
Stack-based buffer overflow in libcsa.a (aka the calendar daemon library) in IBM AIX 5.x through 5.3.10 and 6.x through 6.1.3, and VIOS 2.1
КритическаяCVSS 10,0Готовый эксплойтEPSS 62 %ibm · vios15 окт. 2009 г.
- CVE-2007-167558В плане
Buffer overflow in the CRAM-MD5 authentication mechanism in the IMAP server (nimap.exe) in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.
КритическаяCVSS 10,0Proof of conceptEPSS 61 %ibm · lotus domino28 мар. 2007 г.
- CVE-2007-186858В плане
The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 does not properly handle multipart/form-da
КритическаяCVSS 10,0Готовый эксплойтEPSS 59 %ibm · tivoli provisioning manager os deployment4 апр. 2007 г.
- CVE-2020-428057В плане
IBM QRadar SIEM 7.3 and 7.4 could allow a remote attacker to execute arbitrary commands on the system, caused by insecure deserialization of
ВысокаяCVSS 8,8Эксплойта нетEPSS 73 %ibm · qradar security information and event manager8 окт. 2020 г.