Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

91 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.36%—IBM Cognos Dashboards ON Cloud PAK FOR Data22/10/202317/6/2026
IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in container images which could lead to further attacks against the system. IBM X-Force ID: 260730.
ModificadaAlta (7.5)0.54%—IBM Cloud PAK FOR Data19/7/202317/6/2026
IBM Planning Analytics Cartridge for Cloud Pak for Data 4.0 connects to a CouchDB server. An attacker can exploit an insecure password policy to the CouchDB server and collect sensitive information from the database. IBM X-Force ID: 247905.
ModificadaAlta (7.5)0.57%—IBM Cloud PAK FOR Data19/7/202317/6/2026
Planning Analytics Cartridge for Cloud Pak for Data 4.0 exposes sensitive information in logs which could lead an attacker to exploit this vulnerability to conduct further attacks. IBM X-Force ID: 247896.
ModificadaAlta (7.5)0.66%—IBM Cloud PAK FOR Data19/7/202317/6/2026
Planning Analytics Cartridge for Cloud Pak for Data 4.0 exposes sensitive information in logs which could lead an attacker to exploit this vulnerability to conduct further attacks. IBM X-Force ID: 247896.
ModificadaAlta (7.8)0.50%—IBM Watson Knowledge Catalog ON Cloud PAK FOR Data10/7/202317/6/2026
IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 251782.
ModificadaMedia (6.5)0.98%—IBM Watson Knowledge Catalog ON Cloud PAK FOR Data10/7/202317/6/2026
IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 could allow an authenticated user send a specially crafted request that could cause a denial of service. IBM X-Force ID: 251704.
ModificadaMedia (4.3)0.72%—Cognos Analytics Cartridge FOR IBM Cloud PAK FOR Data10/7/202317/6/2026
IBM Cognos Analytics on Cloud Pak for Data 4.0 could allow an attacker to make system calls that might compromise the security of the containers due to misconfigured security context. IBM X-Force ID: 251465.
ModificadaAlta (7.5)1.3%—IBM Cloud PAK FOR DataIBM Watson Cp4d Data Stores10/7/202317/6/2026
IBM Watson CP4D Data Stores 4.6.0 does not properly allocate resources without limits or throttling which could allow a remote attacker with information specific to the system to cause a denial of service. IBM X-Force ID: 248924.
ModificadaMedia (6.5)0.40%—IBM Watson Machine Learning ON Cloud PAK FOR Data27/4/202317/6/2026
IBM Watson Machine Learning on Cloud Pak for Data 4.0 and 4.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 253350.
ModificadaAlta (7.2)0.87%—IBM Cloud PAK FOR Data26/4/202317/6/2026
IBM Cloud Pak for Data 4.5 and 4.6 could allow a privileged user to upload malicious files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 232034.
ModificadaCrítica (9.8)0.86%—IBM Watson Knowledge Catalog ON Cloud PAK FOR Data12/2/202317/6/2026
IBM Watson Knowledge Catalog on Cloud Pak for Data 4.5.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 237402.
ModificadaMedia (6.5)0.25%—IBM DB2 ON Cloud PAK FOR DataIBM DB2 Warehouse ON Cloud PAK FOR DataIBM Db2u1/12/202217/6/2026
IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 237212.
ModificadaMedia (4.9)0.92%—IBM Data Virtualization ON Cloud PAK FOR Data14/3/202217/6/2026
IBM Data Virtualization on Cloud Pak for Data 1.3.0, 1.4.1, 1.5.0, 1.7.1 and 1.7.3 could allow an authorized user to bypass data masking rules and obtain sensitve information. IBM X-Force ID: 212620.
ModificadaMedia (4.4)0.27%—IBM Cloud PAK FOR Data20/9/202117/6/2026
IBM Cloud Pak for Data 2.5 could allow a local user with special privileges to obtain highly sensitive information. IBM X-Force ID: 209575.
ModificadaMedia (6.5)0.85%—IBM Cloud PAK FOR Data26/5/202117/6/2026
IBM Cloud Pak for Data 3.0 could allow an authenticated user to obtain sensitive information when installed with additional plugins. IBM X-Force ID: 197668.
ModificadaMedia (5.4)0.56%—Watson Assistant FOR IBM Cloud PAK FOR Data9/12/201917/6/2026
IBM Watson Assistant for IBM Cloud Pak for Data 1.0.0 through 1.3.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID:…