IBM kayıtları
ibm üreticisine ait 8.833 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 10 · %0,1
- Silahlaştırılmış
- 60 · %0,7
- Pre-auth RCE
- 456
- Düzeltme kaydı olan
- %1,9
- Yayından KEV’e ortanca
- 1193 gün
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1.548
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor711
- CWE-264 Permissions, Privileges, and Access Controls336
- CWE-20 Improper Input Validation328
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer264
- CWE-352 Cross-Site Request Forgery (CSRF)227
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
8.833 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2014-6271Silahlaştırılmış | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attacgnu · bash · CWE-78 | Kritik9,8 | KEV | %100,0 | 24 Eyl 2014 |
99Hemen | CVE-2017-5638Silahlaştırılmış | The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mesapache · struts · CWE-755 | Kritik9,8 | KEV | %100,0 | 10 Mar 2017 |
99Hemen | CVE-2022-47986Silahlaştırılmış | IBM Aspera Faspex code executionibm · aspera faspex · CWE-502 | Kritik9,8 | KEV | %100,0 | 17 Şub 2023 |
99Hemen | CVE-2014-7169Silahlaştırılmış | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variablgnu · bash · CWE-78 | Kritik9,8 | KEV | %99,9 | 24 Eyl 2014 |
98Hemen | CVE-2015-7450Silahlaştırılmış | Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products alloibm · sterling b2b integrator · CWE-502 | Kritik9,8 | KEV | %97,8 | 2 Oca 2016 |
95Hemen | CVE-2019-4716Silahlaştırılmış | IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "adminibm · planning analytics · CWE-94 | Kritik9,8 | KEV | %86,4 | 18 Ara 2019 |
90Hemen | CVE-2020-4427Silahlaştırılmış | IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configibm · data risk manager · CWE-287 | Kritik9,8 | KEV | %70,0 | 7 May 2020 |
85Hemen | CVE-2020-4428Silahlaştırılmış | IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the systemibm · data risk manager · CWE-78 | Kritik9,1 | KEV | %61,7 | 7 May 2020 |
68Bu hafta | CVE-2001-0797Silahlaştırılmış | Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large numbesgi · irix | Kritik10,0 | — | %94,7 | 12 Ara 2001 |
68Bu hafta | CVE-2015-0235Silahlaştırılmış | Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-depengnu · glibc · CWE-787 | Kritik10,0 | — | %94,6 | 28 Oca 2015 |
68Bu hafta | CVE-2010-0425Silahlaştırılmış | modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, wapache · http server | Kritik10,0 | — | %94,2 | 5 Mar 2010 |
68Bu hafta | CVE-2020-4430Silahlaştırılmış | IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories on the system.ibm · data risk manager · CWE-22 | Orta4,3 | KEV | %68,5 | 7 May 2020 |
63Bu hafta | CVE-2019-4279Silahlaştırılmış | IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted ibm · websphere application server · CWE-502 | Kritik9,8 | — | %79,9 | 17 May 2019 |
63Bu hafta | CVE-2007-4880Silahlaştırılmış | Buffer overflow in the Client Acceptor Daemon (CAD), dsmcad.exe, in certain IBM Tivoli Storage Manager (TSM) clients 5.1 before 5.1.8.1, 5.2ibm · tivoli storage manager client · CWE-119 | Kritik10,0 | — | %75,9 | 27 Eyl 2007 |
62Bu hafta | CVE-2024-22319Kavram kanıtı | IBM Operational Decision Manager JDNI injectionibm · operational decision manager · CWE-74 | Kritik9,8 | — | %76,4 | 1 Şub 2024 |
62Bu hafta | CVE-2017-1092Silahlaştırılmış | IBM Informix Open Admin Tool 11.5, 11.7, and 12.1 could allow an unauthorized user to execute arbitrary code as system admin on Windows servibm · informix open admin tool | Kritik9,8 | — | %75,8 | 22 May 2017 |
61Bu hafta | CVE-2020-4429Silahlaştırılmış | IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrative account.ibm · data risk manager · CWE-798 | Kritik9,8 | — | %72,0 | 7 May 2020 |
61Bu hafta | CVE-2008-4828Silahlaştırılmış | Multiple stack-based buffer overflows in dsmagent.exe in the Remote Agent Service in the IBM Tivoli Storage Manager (TSM) client 5.1.0.0 thribm · tivoli storage manager client · CWE-119 | Kritik10,0 | — | %71,5 | 5 May 2009 |
60Bu hafta | CVE-2020-4211İstismar yok | IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system.ibm · spectrum protect · CWE-78 | Kritik9,8 | — | %71,1 | 24 Şub 2020 |
60Bu hafta | CVE-2003-0694Silahlaştırılmış | The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated usingsendmail · advanced message server | Kritik10,0 | — | %66,2 | 6 Eki 2003 |
59Planlayın | CVE-2008-2240Silahlaştırılmış | Stack-based buffer overflow in the Web Server service in IBM Lotus Domino before 7.0.3 FP1, and 8.x before 8.0.1, allows remote attackers toibm · lotus domino · CWE-119 | Kritik10,0 | — | %64,8 | 22 May 2008 |
59Planlayın | CVE-2009-3699Silahlaştırılmış | Stack-based buffer overflow in libcsa.a (aka the calendar daemon library) in IBM AIX 5.x through 5.3.10 and 6.x through 6.1.3, and VIOS 2.1 ibm · vios · CWE-119 | Kritik10,0 | — | %62,3 | 15 Eki 2009 |
58Planlayın | CVE-2007-1675Kavram kanıtı | Buffer overflow in the CRAM-MD5 authentication mechanism in the IMAP server (nimap.exe) in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.ibm · lotus domino | Kritik10,0 | — | %61,2 | 28 Mar 2007 |
58Planlayın | CVE-2007-1868Silahlaştırılmış | The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 does not properly handle multipart/form-daibm · tivoli provisioning manager os deployment | Kritik10,0 | — | %59,3 | 4 Nis 2007 |
57Planlayın | CVE-2020-4280İstismar yok | IBM QRadar SIEM 7.3 and 7.4 could allow a remote attacker to execute arbitrary commands on the system, caused by insecure deserialization ofibm · qradar security information and event manager · CWE-502 | Yüksek8,8 | — | %73,5 | 8 Eki 2020 |
- CVE-2014-627199Hemen
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100gnu · bash24 Eyl 2014
- CVE-2017-563899Hemen
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mes
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100apache · struts10 Mar 2017
- CVE-2022-4798699Hemen
IBM Aspera Faspex code execution
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100ibm · aspera faspex17 Şub 2023
- CVE-2014-716999Hemen
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100gnu · bash24 Eyl 2014
- CVE-2015-745098Hemen
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allo
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %98ibm · sterling b2b integrator2 Oca 2016
- CVE-2019-471695Hemen
IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %86ibm · planning analytics18 Ara 2019
- CVE-2020-442790Hemen
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when config
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %70ibm · data risk manager7 May 2020
- CVE-2020-442885Hemen
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system
KritikCVSS 9,1KEVSilahlaştırılmışEPSS %62ibm · data risk manager7 May 2020
- CVE-2001-079768Bu hafta
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large numbe
KritikCVSS 10,0SilahlaştırılmışEPSS %95sgi · irix12 Ara 2001
- CVE-2015-023568Bu hafta
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-depen
KritikCVSS 10,0SilahlaştırılmışEPSS %95gnu · glibc28 Oca 2015
- CVE-2010-042568Bu hafta
modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, w
KritikCVSS 10,0SilahlaştırılmışEPSS %94apache · http server5 Mar 2010
- CVE-2020-443068Bu hafta
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories on the system.
OrtaCVSS 4,3KEVSilahlaştırılmışEPSS %69ibm · data risk manager7 May 2020
- CVE-2019-427963Bu hafta
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted
KritikCVSS 9,8SilahlaştırılmışEPSS %80ibm · websphere application server17 May 2019
- CVE-2007-488063Bu hafta
Buffer overflow in the Client Acceptor Daemon (CAD), dsmcad.exe, in certain IBM Tivoli Storage Manager (TSM) clients 5.1 before 5.1.8.1, 5.2
KritikCVSS 10,0SilahlaştırılmışEPSS %76ibm · tivoli storage manager client27 Eyl 2007
- CVE-2024-2231962Bu hafta
IBM Operational Decision Manager JDNI injection
KritikCVSS 9,8Kavram kanıtıEPSS %76ibm · operational decision manager1 Şub 2024
- CVE-2017-109262Bu hafta
IBM Informix Open Admin Tool 11.5, 11.7, and 12.1 could allow an unauthorized user to execute arbitrary code as system admin on Windows serv
KritikCVSS 9,8SilahlaştırılmışEPSS %76ibm · informix open admin tool22 May 2017
- CVE-2020-442961Bu hafta
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrative account.
KritikCVSS 9,8SilahlaştırılmışEPSS %72ibm · data risk manager7 May 2020
- CVE-2008-482861Bu hafta
Multiple stack-based buffer overflows in dsmagent.exe in the Remote Agent Service in the IBM Tivoli Storage Manager (TSM) client 5.1.0.0 thr
KritikCVSS 10,0SilahlaştırılmışEPSS %71ibm · tivoli storage manager client5 May 2009
- CVE-2020-421160Bu hafta
IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system.
KritikCVSS 9,8İstismar yokEPSS %71ibm · spectrum protect24 Şub 2020
- CVE-2003-069460Bu hafta
The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using
KritikCVSS 10,0SilahlaştırılmışEPSS %66sendmail · advanced message server6 Eki 2003
- CVE-2008-224059Planlayın
Stack-based buffer overflow in the Web Server service in IBM Lotus Domino before 7.0.3 FP1, and 8.x before 8.0.1, allows remote attackers to
KritikCVSS 10,0SilahlaştırılmışEPSS %65ibm · lotus domino22 May 2008
- CVE-2009-369959Planlayın
Stack-based buffer overflow in libcsa.a (aka the calendar daemon library) in IBM AIX 5.x through 5.3.10 and 6.x through 6.1.3, and VIOS 2.1
KritikCVSS 10,0SilahlaştırılmışEPSS %62ibm · vios15 Eki 2009
- CVE-2007-167558Planlayın
Buffer overflow in the CRAM-MD5 authentication mechanism in the IMAP server (nimap.exe) in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.
KritikCVSS 10,0Kavram kanıtıEPSS %61ibm · lotus domino28 Mar 2007
- CVE-2007-186858Planlayın
The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 does not properly handle multipart/form-da
KritikCVSS 10,0SilahlaştırılmışEPSS %59ibm · tivoli provisioning manager os deployment4 Nis 2007
- CVE-2020-428057Planlayın
IBM QRadar SIEM 7.3 and 7.4 could allow a remote attacker to execute arbitrary commands on the system, caused by insecure deserialization of
YüksekCVSS 8,8İstismar yokEPSS %73ibm · qradar security information and event manager8 Eki 2020