Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

100 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.46%—IBM Spectrum Protect Plus24/2/202017/6/2026
IBM Spectrum Protect Plus 10.1.0 and 10.5.0, when protecting Microsoft SQL or Microsoft Exchange, could allow an attacker with intimate knowledge of the system to obtain highly sensitive information.
ModificadaMedia (4.4)0.30%—IBM Spectrum Protect Backup-archive Client25/11/201917/6/2026
IBM Spectrum Protect Backup-Archive Client 7.1 and 8.1 may be vulnerable to a denial of service attack due to a timing issue between client and server TCP/IP communications. IBM X-Force ID: 162477.
ModificadaMedia (4.4)0.31%—IBM Spectrum ProtectIBM Spectrum Protect FOR Virtual Environments25/11/201917/6/2026
IBM Spectrum Protect Backup-Archive Client and IBM Spectrum Protect for Virtual Environments 7.1 and 8.1 creates directories/files in the CIT sub directory that are read/writable by everyone. IBM X-Force ID: 155551.
ModificadaAlta (7.1)0.27%—IBM Spectrum Protect Plus12/11/201917/6/2026
IBM Spectrum Protect Plus 10.1.0 through 10.1.4 uses insecure file permissions on restored files and directories in Windows which could allow a local user to obtain sensitive information or perform unauthorized actions. IBM X-Force ID: 170963.
ModificadaAlta (7.8)0.44%—IBM Spectrum Protect22/7/201917/6/2026
The IBM Spectrum Protect 7.1 and 8.1 Backup-Archive Client is vulnerable to a buffer overflow. This could allow execution of arbitrary code on the local system or the application to crash. IBM X-Force ID: 160200.
ModificadaMedia (4.4)0.32%—IBM Spectrum Protect22/7/201917/6/2026
A IBM Spectrum Protect 7.l client backup or archive operation running for an HP-UX VxFS object is silently skipping Access Control List (ACL) entries from backup or archive if there are more than twelve ACL entries associated with the object in total. As a result, it could allow a local attacker to restore or retrieve…
ModificadaAlta (7.1)0.31%—IBM Spectrum Protect2/7/201917/6/2026
IBM Tivoli Storage Manager Server (IBM Spectrum Protect 7.1 and 8.1) could allow a local user to replace existing databases by restoring old data. IBM X-Force ID: 158336.
ModificadaMedia (5.3)1.6%—IBM Spectrum Protect Operations Center2/7/201917/6/2026
IBM Spectrum Protect Operations Center 7.1 and 8.1 could allow a remote attacker to obtain sensitive information, caused by an error message containing a stack trace. By creating an error with a stack trace, an attacker could exploit this vulnerability to potentially obtain details on the Operations Center…
ModificadaAlta (7.8)0.53%—IBM Spectrum Protect Operations Center2/7/201917/6/2026
IBM Spectrum Protect Servers 7.1 and 8.1 and Storage Agents could allow a local attacker to gain elevated privileges on the system, caused by loading a specially crafted library loaded by the dsmqsan module. By setting up such a library, a local attacker could exploit this vulnerability to gain root privileges on the…
ModificadaCrítica (9.8)7.0%—IBM Spectrum Protect Operations Center2/7/201917/6/2026
IBM Spectrum Protect Servers 7.1 and 8.1 and Storage Agents are vulnerable to a stack-based buffer overflow, caused by improper bounds checking by servers and storage agents in response to specifically crafted communication exchanges. By sending an overly long request, a remote attacker could overflow a buffer and…
ModificadaMedia (6.7)0.40%—IBM Spectrum Protect Plus1/7/201917/6/2026
When using IBM Spectrum Protect Plus 10.1.0, 10.1.2, and 10.1.3 to protect Oracle or MongoDB databases, a redirected restore operation may result in an escalation of user privileges. IBM X-Force ID: 162165.
ModificadaMedia (6.7)0.46%—IBM Spectrum Protect Plus1/7/201917/6/2026
When using IBM Spectrum Protect Plus 10.1.0, 10.1.2, and 10.1.3 to protect Oracle, DB2 or MongoDB databases, a redirected restore operation specifying a target path may allow execution of arbitrary code on the system. IBM X-Force ID: 161667,
ModificadaMedia (6.5)0.33%—IBM Spectrum Protect Plus19/6/201917/6/2026
IBM Spectrum Protect Plus 10.1.2 may display the vSnap CIFS password in the IBM Spectrum Protect Plus Joblog. This can result in an attacker gaining access to sensitive information as well as vSnap. IBM X-Force ID: 162173.
ModificadaMedia (4.7)0.22%—IBM Spectrum Protect Backup-archive ClientIBM Spectrum Protect FOR Virtual Environments8/4/201917/6/2026
In a certain atypical IBM Spectrum Protect 7.1 and 8.1 configurations, the node password could be displayed in plain text in the IBM Spectrum Protect client trace file. IBM X-Force ID: 151968.
ModificadaMedia (6.1)1.2%—IBM Spectrum Protect Backup-archive Client8/4/201917/6/2026
IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks…
ModificadaMedia (5.5)0.30%—IBM Spectrum Protect Backup-archive ClientIBM Spectrum Protect FOR Virtual Environments8/4/201917/6/2026
IBM Spectrum Protect 7.1 and 8.1 is affected by a password exposure vulnerability caused by insecure file permissions. IBM X-Force ID: 148872.
ModificadaMedia (4.4)0.33%—IBM Spectrum Protect2/4/201917/6/2026
IBM Tivoli Storage Manager (IBM Spectrum Protect 8.1.7) could allow a user to restore files and directories using IBM Spectrum Prootect Client Web User Interface on Windows that they should not have access to due to incorrect file permissions. IBM X-Force ID: 157981.
ModificadaAlta (7.5)2.4%—IBM Spectrum ProtectIBM Tivoli Storage ManagerIBM Spectrum Protect Manager FOR Virtual Environments Data Protection FOR VmwareIBM Tivoli Storage Manager FOR Virtual Environments Data Protection FOR Vmware+212/11/201817/6/2026
IBM Spectrum Protect 7.1 and 8.1 dsmc and dsmcad processes incorrectly accumulate TCP/IP sockets in a CLOSE_WAIT state. This can cause TCP/IP resource leakage and may result in a denial of service. IBM X-Force ID: 148871.
ModificadaMedia (4.4)0.39%—IBM Spectrum Protect Server2/11/201817/6/2026
IBM Spectrum Protect Server 7.1 and 8.1 could disclose highly sensitive information via trace logs to a local privileged user. IBM X-Force ID: 148873.
ModificadaAlta (7.5)1.1%—IBM Spectrum Protect ClientIBM Spectrum Protect FOR Virtual Environments26/9/201817/6/2026
IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive information. IBM X-Force ID: 148870.
ModificadaAlta (7.8)0.38%—IBM Spectrum Protect Plus26/9/201817/6/2026
IBM Spectrum Protect Plus 10.1.0 and 10.1.1 could disclose sensitive information when an authorized user executes a test operation, the user id an password may be displayed in plain text within an instrumentation log file. IBM X-Force ID: 148622.
ModificadaAlta (7.5)0.97%—IBM Spectrum Protect ClientIBM Spectrum Protect FOR Virtual Environments26/9/201817/6/2026
IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 142649.
ModificadaAlta (8.1)0.91%—IBM Spectrum Protect FOR Space ManagementIBM Spectrum Protect FOR Virtual EnvironmentsIBM Spectrum Protect Snapshot4/4/201817/6/2026
The GSKit (IBM Spectrum Protect 7.1 and 7.2) and (IBM Spectrum Protect Snapshot 4.1.3, 4.1.4, and 4.1.6) CMS KDB logic fails to salt the hash function resulting in weaker than expected protection of passwords. A weak password may be recovered. Note: After update the customer should change password to ensure the new…
ModificadaCrítica (10)2.5%—IBM Spectrum Protect FOR Virtual EnvironmentsIBM Spectrum Protect Snapshot2/1/201617/6/2026
The Data Protection extension in the VMware GUI in IBM Tivoli Storage Manager for Virtual Environments: Data Protection for VMware (aka Spectrum Protect for Virtual Environments) 7.1 before 7.1.3.0 and Tivoli Storage FlashCopy Manager for VMware (aka Spectrum Protect Snapshot) 4.1 before 4.1.3.0 allows remote…
ModificadaAlta (8.5)0.98%—IBM Spectrum Protect FOR Virtual EnvironmentsIBM Spectrum Protect Snapshot2/1/201617/6/2026
The Data Protection extension in the VMware GUI in IBM Tivoli Storage Manager for Virtual Environments: Data Protection for VMware (aka Spectrum Protect for Virtual Environments) 7.1 before 7.1.4 and Tivoli Storage FlashCopy Manager for VMware (aka Spectrum Protect Snapshot) 4.1 before 4.1.4 allows remote…
Orbitaley — Vulnerabilidades