Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

281 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.44%—IBM Spectrum Protect22/7/201917/6/2026
The IBM Spectrum Protect 7.1 and 8.1 Backup-Archive Client is vulnerable to a buffer overflow. This could allow execution of arbitrary code on the local system or the application to crash. IBM X-Force ID: 160200.
ModificadaMedia (4.4)0.32%—IBM Spectrum Protect22/7/201917/6/2026
A IBM Spectrum Protect 7.l client backup or archive operation running for an HP-UX VxFS object is silently skipping Access Control List (ACL) entries from backup or archive if there are more than twelve ACL entries associated with the object in total. As a result, it could allow a local attacker to restore or retrieve…
ModificadaMedia (6.1)0.79%—Siemens Spectrum Power 3Siemens Spectrum Power 4Siemens Spectrum Power 5Siemens Spectrum Power 711/7/201917/6/2026
A vulnerability has been identified in Spectrum Power 3 (Corporate User Interface) (All versions <= v3.11), Spectrum Power 4 (Corporate User Interface) (Version v4.75), Spectrum Power 5 (Corporate User Interface) (All versions < v5.50), Spectrum Power 7 (Corporate User Interface) (All versions <= v2.20). The web…
ModificadaAlta (7.1)0.31%—IBM Spectrum Protect2/7/201917/6/2026
IBM Tivoli Storage Manager Server (IBM Spectrum Protect 7.1 and 8.1) could allow a local user to replace existing databases by restoring old data. IBM X-Force ID: 158336.
ModificadaMedia (5.3)1.6%—IBM Spectrum Protect Operations Center2/7/201917/6/2026
IBM Spectrum Protect Operations Center 7.1 and 8.1 could allow a remote attacker to obtain sensitive information, caused by an error message containing a stack trace. By creating an error with a stack trace, an attacker could exploit this vulnerability to potentially obtain details on the Operations Center…
ModificadaAlta (7.8)0.53%—IBM Spectrum Protect Operations Center2/7/201917/6/2026
IBM Spectrum Protect Servers 7.1 and 8.1 and Storage Agents could allow a local attacker to gain elevated privileges on the system, caused by loading a specially crafted library loaded by the dsmqsan module. By setting up such a library, a local attacker could exploit this vulnerability to gain root privileges on the…
ModificadaCrítica (9.8)7.0%—IBM Spectrum Protect Operations Center2/7/201917/6/2026
IBM Spectrum Protect Servers 7.1 and 8.1 and Storage Agents are vulnerable to a stack-based buffer overflow, caused by improper bounds checking by servers and storage agents in response to specifically crafted communication exchanges. By sending an overly long request, a remote attacker could overflow a buffer and…
ModificadaMedia (6.7)0.40%—IBM Spectrum Protect Plus1/7/201917/6/2026
When using IBM Spectrum Protect Plus 10.1.0, 10.1.2, and 10.1.3 to protect Oracle or MongoDB databases, a redirected restore operation may result in an escalation of user privileges. IBM X-Force ID: 162165.
ModificadaMedia (6.7)0.46%—IBM Spectrum Protect Plus1/7/201917/6/2026
When using IBM Spectrum Protect Plus 10.1.0, 10.1.2, and 10.1.3 to protect Oracle, DB2 or MongoDB databases, a redirected restore operation specifying a target path may allow execution of arbitrary code on the system. IBM X-Force ID: 161667,
ModificadaMedia (6.5)0.33%—IBM Spectrum Protect Plus19/6/201917/6/2026
IBM Spectrum Protect Plus 10.1.2 may display the vSnap CIFS password in the IBM Spectrum Protect Plus Joblog. This can result in an attacker gaining access to sensitive information as well as vSnap. IBM X-Force ID: 162173.
ModificadaMedia (5.9)2.1%—IBM Spectrum Control29/5/201917/6/2026
IBM Tivoli Storage Productivity Center 5.2.13 through 5.3.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. X-Force…
ModificadaMedia (6.1)1.3%—IBM Spectrum Control29/5/201917/6/2026
IBM Tivoli Storage Productivity Center 5.2.13 through 5.3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158333.
ModificadaMedia (5.5)0.35%—IBM Spectrum Scale13/5/201917/6/2026
A security vulnerability has been identified in IBM Spectrum Scale 4.1.1, 4.2.0, 4.2.1, 4.2.2, 4.2.3, and 5.0.0 with CES stack enabled that could allow sensitive data to be included with service snaps. IBM X-Force ID: 160011.
ModificadaMedia (6.3)0.80%—IBM Spectrum ControlIBM Tivoli Storage Productivity Center9/5/201917/6/2026
IBM Tivoli Storage Productivity Center (IBM Spectrum Control Standard Edition 5.2.1 through 5.2.17) allows users to remain idle within the application even when a user has logged out. Utilizing the application back button users can remain logged in as the current user for a short period of time, therefore users are…
ModificadaAlta (8.8)4.3%—IBM Spectrum ControlIBM Tivoli Storage Productivity Center9/5/201917/6/2026
IBM Tivoli Storage Productivity Center (IBM Spectrum Control Standard Edition 5.2.1 through 5.2.17) could allow a remote attacker to execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 157063.
ModificadaCrítica (9.8)2.3%—Siemens Spectrum Power 417/4/201917/6/2026
A vulnerability has been identified in Spectrum Power 4 (with Web Office Portal). An attacker with network access to the web server on port 80/TCP or 443/TCP could execute system commands with administrative privileges. The security vulnerability could be exploited by an unauthenticated attacker with network access to…
ModificadaMedia (4.7)0.22%—IBM Spectrum Protect Backup-archive ClientIBM Spectrum Protect FOR Virtual Environments8/4/201917/6/2026
In a certain atypical IBM Spectrum Protect 7.1 and 8.1 configurations, the node password could be displayed in plain text in the IBM Spectrum Protect client trace file. IBM X-Force ID: 151968.
ModificadaMedia (6.1)1.2%—IBM Spectrum Protect Backup-archive Client8/4/201917/6/2026
IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks…
ModificadaMedia (5.5)0.30%—IBM Spectrum Protect Backup-archive ClientIBM Spectrum Protect FOR Virtual Environments8/4/201917/6/2026
IBM Spectrum Protect 7.1 and 8.1 is affected by a password exposure vulnerability caused by insecure file permissions. IBM X-Force ID: 148872.
ModificadaMedia (4.4)0.33%—IBM Spectrum Protect2/4/201917/6/2026
IBM Tivoli Storage Manager (IBM Spectrum Protect 8.1.7) could allow a user to restore files and directories using IBM Spectrum Prootect Client Web User Interface on Windows that they should not have access to due to incorrect file permissions. IBM X-Force ID: 157981.
ModificadaCrítica (9.8)2.1%—Baxter Sigma Spectrum Infusion System Firmware26/3/201917/6/2026
An unauthenticated remote attacker may be able to execute commands to view wireless account credentials that are stored in cleartext on Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16, which may allow an attacker to gain access the host network. Baxter…
ModificadaCrítica (9.8)2.6%—Baxter Sigma Spectrum Infusion System Firmware26/3/201917/6/2026
Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 is remotely accessible via Port 22/SSH without authentication. A remote attacker may be able to make unauthorized configuration changes to the WBM, as well as issue commands to access account credentials…
ModificadaMedia (6.8)0.38%—Baxter Sigma Spectrum Infusion System Firmware26/3/201917/6/2026
Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 contains a hard-coded password, which provides access to basic biomedical information, limited device settings, and network configuration of the WBM, if connected. The hard-coded password may allow an…
ModificadaCrítica (9.8)1.6%—Baxter Sigma Spectrum Infusion System Firmware26/3/201917/6/2026
Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 has a default account with hard-coded credentials used with the FTP protocol. Baxter asserts no files can be transferred to or from the WBM using this account. Baxter has released a new version of the…
ModificadaMedia (6.5)1.9%—IBM Spectrum Virtualize SoftwareIBM Spectrum Virtualize Software FOR Public Cloud27/2/201917/6/2026
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products versions 7.5 through 8.2 could allow an authenticated user to download arbitrary files from the operating system. IBM X-Force ID: 148757.
Orbitaley — Vulnerabilidades