Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
281 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.3) | 0.39% | — | IBM Spectrum Scale | 8/1/2019 | 17/6/2026 | IBM Spectrum Scale (GPFS) 4.1.1, 4.2.0, 4.2.1, 4.2.2, 4.2.3, and 5.0.0 where the use of Local Read Only Cache (LROC) is enabled may caused read operation on a file to return data from a different file. IBM X-Force ID: 154440. | |
| Modificada | Alta (7.5) | 2.4% | — | IBM Spectrum ProtectIBM Tivoli Storage ManagerIBM Spectrum Protect Manager FOR Virtual Environments Data Protection FOR VmwareIBM Tivoli Storage Manager FOR Virtual Environments Data Protection FOR Vmware+2 | 12/11/2018 | 17/6/2026 | IBM Spectrum Protect 7.1 and 8.1 dsmc and dsmcad processes incorrectly accumulate TCP/IP sockets in a CLOSE_WAIT state. This can cause TCP/IP resource leakage and may result in a denial of service. IBM X-Force ID: 148871. | |
| Modificada | Media (4.4) | 0.39% | — | IBM Spectrum Protect Server | 2/11/2018 | 17/6/2026 | IBM Spectrum Protect Server 7.1 and 8.1 could disclose highly sensitive information via trace logs to a local privileged user. IBM X-Force ID: 148873. | |
| Modificada | Media (5.3) | 0.33% | — | IBM Spectrum LSF | 11/10/2018 | 17/6/2026 | IBM Spectrum LSF 9.1.1 9.1.2, 9.1.3, and 10.1 could allow a local user to change their job user at job submission time due to improper file permission settings. IBM X-Force ID: 147439. | |
| Modificada | Media (5.4) | 0.66% | — | IBM Spectrum Symphony | 11/10/2018 | 17/6/2026 | IBM Spectrum Symphony 7.2.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 146341. | |
| Modificada | Media (5.5) | 0.33% | — | IBM Spectrum Scale | 5/10/2018 | 17/6/2026 | IBM GPFS (IBM Spectrum Scale 4.1.1.0, 4.1.1.20, 4.2.0.0, 4.2.3.10, 5.0.0 and 5.0.1.2) command line utility allows an unprivileged, authenticated user with access to a GPFS node to forcefully terminate GPFS and deny access to data available through GPFS. IBM X-Force ID: 148806. | |
| Modificada | Media (5.5) | 0.40% | — | IBM Spectrum Scale | 5/10/2018 | 17/6/2026 | IBM Spectrum Scale 4.1.1.0, 4.1.1.20, 4.2.0.0, 4.2.3.10, 5.0.0 and 5.0.1.2 could allow an unprivileged, authenticated user with access to a GPFS node to read arbitrary files available on this node. IBM X-Force ID: 147373. | |
| Modificada | Media (5.4) | 0.71% | — | IBM Platform SymphonyIBM Spectrum Symphony | 28/9/2018 | 17/6/2026 | IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL… | |
| Modificada | Alta (7.1) | 1.9% | — | IBM Platform SymphonyIBM Spectrum Symphony | 28/9/2018 | 17/6/2026 | IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 are vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 146189. | |
| Modificada | Alta (7.5) | 1.1% | — | IBM Spectrum Protect ClientIBM Spectrum Protect FOR Virtual Environments | 26/9/2018 | 17/6/2026 | IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive information. IBM X-Force ID: 148870. | |
| Modificada | Alta (7.8) | 0.38% | — | IBM Spectrum Protect Plus | 26/9/2018 | 17/6/2026 | IBM Spectrum Protect Plus 10.1.0 and 10.1.1 could disclose sensitive information when an authorized user executes a test operation, the user id an password may be displayed in plain text within an instrumentation log file. IBM X-Force ID: 148622. | |
| Modificada | Alta (7.5) | 0.97% | — | IBM Spectrum Protect ClientIBM Spectrum Protect FOR Virtual Environments | 26/9/2018 | 17/6/2026 | IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 142649. | |
| Modificada | Media (6.5) | 0.33% | — | IBM Spectrum Scale | 19/9/2018 | 17/6/2026 | IBM GPFS (IBM Spectrum Scale 5.0.1.0 and 5.0.1.1) allows a local, unprivileged user to cause a kernel panic on a node running GPFS by accessing a file that is stored on a GPFS file system with mmap, or by executing a crafted file stored on a GPFS file system. IBM X-Force ID: 148805. | |
| Modificada | Media (6.5) | 1.3% | — | IBM Platform SymphonyIBM Spectrum Symphony | 28/8/2018 | 17/6/2026 | IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 contain an information disclosure vulnerability that could allow an authenticated attacker to obtain highly sensitive information. IBM X-Force ID: 146340. | |
| Modificada | Alta (8.8) | 2.4% | — | IBM Platform SymphonyIBM Spectrum Symphony | 1/8/2018 | 17/6/2026 | IBM Spectrum Symphony and Platform Symphony 7.1.2 and 7.2.0.2 could allow an authenticated user to execute arbitrary commands due to improper handling of user supplied input. IBM X-Force ID: 143622. | |
| Modificada | Alta (7.8) | 0.38% | — | IBM General Parallel File SystemIBM Spectrum Scale | 13/6/2018 | 17/6/2026 | A vulnerability in GSKit affects IBM Spectrum Scale 4.1.1, 4.2.0, 4.2.1, 4.2.3, and 5.0.0 that could allow a local attacker to obtain control of the Spectrum Scale daemon and to access and modify files in the Spectrum Scale file system, and possibly to obtain administrator privileges on the node. IBM X-Force ID:… | |
| Modificada | Media (5.3) | 0.81% | — | IBM Storwize V7000 FirmwareIBM Storwize V5000 FirmwareIBM Storwize V3700 FirmwareIBM Storwize V3500 Firmware+4 | 17/5/2018 | 17/6/2026 | IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products (6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) use weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM… | |
| Modificada | Media (5.3) | 1.3% | — | IBM Storwize V7000 FirmwareIBM Storwize V5000 FirmwareIBM Storwize V3700 FirmwareIBM Storwize V3500 Firmware+4 | 17/5/2018 | 17/6/2026 | IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) could allow an authenticated user to obtain the private key which could make intercepting GUI communications possible. IBM… | |
| Modificada | Media (6.5) | 1.6% | — | IBM Storwize V7000 FirmwareIBM Storwize V5000 FirmwareIBM Storwize V3700 FirmwareIBM Storwize V3500 Firmware+4 | 17/5/2018 | 17/6/2026 | IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) could allow an authenticated user to obtain sensitive information that they should not have authorization to read. IBM X-Force… | |
| Modificada | Media (6.5) | 1.4% | — | IBM Storwize V7000 FirmwareIBM Storwize V5000 FirmwareIBM Storwize V3700 FirmwareIBM Storwize V3500 Firmware+4 | 17/5/2018 | 17/6/2026 | IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) could allow an authenticated user to access system files they should not have access to some of which could contain account… | |
| Modificada | Alta (7.6) | 1.2% | — | IBM Storwize V7000 FirmwareIBM Storwize V5000 FirmwareIBM Storwize V3700 FirmwareIBM Storwize V3500 Firmware+4 | 17/5/2018 | 17/6/2026 | IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) could allow an authenticated user to access system files they should not have access to including deleting files or causing a… | |
| Modificada | Media (5.4) | 0.96% | — | IBM Storwize V7000 FirmwareIBM Storwize V5000 FirmwareIBM Storwize V3700 FirmwareIBM Storwize V3500 Firmware+4 | 17/5/2018 | 17/6/2026 | IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus… | |
| Modificada | Alta (7.5) | 2.2% | — | IBM Storwize V7000 FirmwareIBM Storwize V5000 FirmwareIBM Storwize V3700 FirmwareIBM Storwize V3500 Firmware+4 | 17/5/2018 | 17/6/2026 | IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) web handler /DLSnap could allow an unauthenticated attacker to read arbitrary files on the system. IBM X-Force ID: 139566. | |
| Modificada | Alta (8.8) | 0.91% | — | IBM Storwize V7000 FirmwareIBM Storwize V5000 FirmwareIBM Storwize V3700 FirmwareIBM Storwize V3500 Firmware+4 | 17/5/2018 | 17/6/2026 | IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) are vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions… | |
| Modificada | Alta (7.5) | 2.5% | — | IBM Storwize V7000 FirmwareIBM Storwize V5000 FirmwareIBM Storwize V3700 FirmwareIBM Storwize V3500 Firmware+4 | 17/5/2018 | 17/6/2026 | IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) web handler /DownloadFile does not require authentication to read arbitrary files from the system. IBM X-Force ID: 139473. |