Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
281 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.1) | 0.34% | — | IBM Spectrum Scale | 19/5/2020 | 17/6/2026 | The Spectrum Scale 4.2.0.0 through 4.2.3.21 and 5.0.0.0 through 5.0.4.3 file system component is affected by a denial of service vulnerability in its kernel module that could allow an attacker to cause a denial of service condition on the affected system. To exploit this vulnerability, a local attacker could invoke a… | |
| Modificada | Media (5.4) | 1.4% | — | IBM Spectrum Protect Plus | 4/5/2020 | 17/6/2026 | IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to create arbitrary files on the system. IBM X-Force ID: 175019. | |
| Modificada | Crítica (9.8) | 8.1% | — | IBM Spectrum Protect | 23/4/2020 | 17/6/2026 | IBM Spectrum Protect 7.1 and 8.1 server is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. This could allow a remote attacker to execute arbitrary code on the system with the privileges of an administrator or user associated with the Spectrum Protect server or cause the Spectrum… | |
| Modificada | Alta (7.8) | 0.40% | — | IBM Spectrum Scale | 3/4/2020 | 17/6/2026 | IBM Spectrum Scale 4.2 and 5.0 could allow a local unprivileged attacker with intimate knowledge of the enviornment to execute commands as root using specially crafted input. IBM X-Force ID: 175977. | |
| Modificada | Alta (8.8) | 4.6% | — | IBM Spectrum Protect PlusIBM Spectrum Scale | 31/3/2020 | 17/6/2026 | IBM Spectrum Scale and IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 175419. | |
| Modificada | Alta (8.8) | 66% | — | IBM Spectrum Protect PlusIBM Spectrum Scale | 31/3/2020 | 17/6/2026 | IBM Spectrum Scale and IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 175418. | |
| Modificada | Media (6.5) | 2.0% | — | IBM Spectrum Protect Plus | 31/3/2020 | 17/6/2026 | IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request to overwrite or create arbitrary files on the system. IBM X-Force ID: 175417. | |
| Modificada | Alta (7.5) | 1.6% | — | IBM Spectrum Protect Plus | 31/3/2020 | 17/6/2026 | IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to arbitrary delete a directory caused by improper validation of user-supplied input. IBM X-Force ID: 175026. | |
| Modificada | Crítica (9.8) | 1.8% | — | IBM Spectrum Protect Plus | 31/3/2020 | 17/6/2026 | IBM Spectrum Protect Plus 10.1.0 through 10.1.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 174975. | |
| Modificada | Alta (8.8) | 4.6% | — | IBM Spectrum Protect Plus | 31/3/2020 | 17/6/2026 | IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to execute arbitrary commands on the system in the context of root user, caused by improper validation of user-supplied input. IBM X-Force ID: 174966. | |
| Modificada | Media (6.1) | 0.78% | — | Siemens Spectrum Power 5 | 10/3/2020 | 17/6/2026 | A vulnerability has been identified in Spectrum Power™ 5 (All versions < v5.50 HF02). The web server could allow Cross-Site Scripting (XSS) attacks if unsuspecting users are tricked into accessing a malicious link. User interaction is required for a successful exploitation. If deployed according to recommended system… | |
| Modificada | Alta (7.5) | 1.3% | — | IBM Spectrum Scale | 9/3/2020 | 17/6/2026 | The IBM Spectrum Scale 4.2 and 5.0 file system component is affected by a denial of service security vulnerability. An attacker can force the Spectrum Scale mmfsd/mmsdrserv daemons to unexpectedly exit, impacting the functionality of the Spectrum Scale cluster and the availability of file systems managed by Spectrum… | |
| Modificada | Alta (7.8) | 0.27% | — | IBM Platform LSFIBM Spectrum Computing FOR High Performance AnalyticsIBM Spectrum LSF | 5/3/2020 | 17/6/2026 | IBM Platform LSF 9.1 and 10.1, IBM Spectrum LSF Suite 10.2, and IBM Spectrum Suite for HPA 10.2 could allow a local user to escalate their privileges due to weak file permissions when specific debug settings are enabled in a Linux or Unix enviornment. IBM X-Force ID: 176137. | |
| Modificada | Crítica (9.8) | 15% | — | IBM Spectrum Protect | 24/2/2020 | 17/6/2026 | IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175091. | |
| Modificada | Crítica (9.8) | 15% | — | IBM Spectrum Protect | 24/2/2020 | 17/6/2026 | IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175024. | |
| Modificada | Crítica (9.8) | 15% | — | IBM Spectrum Protect | 24/2/2020 | 17/6/2026 | IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175023. | |
| Modificada | Crítica (9.8) | 71% | — | IBM Spectrum Protect | 24/2/2020 | 17/6/2026 | IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175022. | |
| Modificada | Crítica (9.8) | 15% | — | IBM Spectrum Protect | 24/2/2020 | 17/6/2026 | IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175020. | |
| Modificada | Media (5.3) | 0.46% | — | IBM Spectrum Protect Plus | 24/2/2020 | 17/6/2026 | IBM Spectrum Protect Plus 10.1.0 and 10.5.0, when protecting Microsoft SQL or Microsoft Exchange, could allow an attacker with intimate knowledge of the system to obtain highly sensitive information. | |
| Modificada | Alta (8.8) | 4.0% | — | IBM Spectrum Scale | 11/12/2019 | 17/6/2026 | IBM Spectrum Scale 4.2 and 5.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 172093. | |
| Modificada | Media (5.4) | 0.56% | — | IBM Spectrum Scale | 11/12/2019 | 17/6/2026 | IBM Spectrum Scale 4.2 and 5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 171247. | |
| Modificada | Media (4.4) | 0.30% | — | IBM Spectrum Protect Backup-archive Client | 25/11/2019 | 17/6/2026 | IBM Spectrum Protect Backup-Archive Client 7.1 and 8.1 may be vulnerable to a denial of service attack due to a timing issue between client and server TCP/IP communications. IBM X-Force ID: 162477. | |
| Modificada | Media (4.4) | 0.31% | — | IBM Spectrum ProtectIBM Spectrum Protect FOR Virtual Environments | 25/11/2019 | 17/6/2026 | IBM Spectrum Protect Backup-Archive Client and IBM Spectrum Protect for Virtual Environments 7.1 and 8.1 creates directories/files in the CIT sub directory that are read/writable by everyone. IBM X-Force ID: 155551. | |
| Modificada | Alta (7.1) | 0.27% | — | IBM Spectrum Protect Plus | 12/11/2019 | 17/6/2026 | IBM Spectrum Protect Plus 10.1.0 through 10.1.4 uses insecure file permissions on restored files and directories in Windows which could allow a local user to obtain sensitive information or perform unauthorized actions. IBM X-Force ID: 170963. | |
| Modificada | Alta (7.8) | 1.2% | — | IBM Spectrum Scale | 9/10/2019 | 17/6/2026 | A security vulnerability has been identified in all levels of IBM Spectrum Scale V5.0.0.0 through V5.0.3.2 and IBM Spectrum Scale V4.2.0.0 through V4.2.3.17 that could allow a local attacker to obtain root privilege by injecting parameters into setuid files. |