Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
–

100 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)0.37%—IBM Spectrum Protect Server20/6/202517/6/2026
IBM Spectrum Protect Server 8.1 through 8.1.26 could allow attacker to bypass authentication due to improper session authentication which can result in access to unauthorized resources.
ModificadaAlta (7.5)0.61%—IBM Spectrum Protect Plus2/2/202417/6/2026
IBM Storage Protect Plus Server 10.1.0 through 10.1.15.2 Admin Console could allow a remote attacker to obtain sensitive information due to improper validation of unsecured endpoints which could be used in further attacks against the system. IBM X-Force ID: 270599.
ModificadaMedia (4.7)0.13%—IBM Spectrum Protect ClientIBM Spectrum Protect FOR Space ManagementIBM Spectrum Protect FOR Virtual Environments19/7/202317/6/2026
IBM Spectrum Protect 8.1.0.0 through 8.1.17.0 could allow a local user to cause a denial of service due to due to improper time-of-check to time-of-use functionality. IBM X-Force ID: 256012.
ModificadaAlta (7.8)0.16%—IBM Spectrum Protect Backup-archive Client22/6/202317/6/2026
IBM Spectrum Protect Backup-Archive Client 8.1.0.0 through 8.1.17.2 may allow a local user to escalate their privileges due to improper access controls.
ModificadaMedia (4.9)0.57%—IBM Spectrum Protect12/5/202317/6/2026
IBM Spectrum Protect Plus Server 10.1.13, under specific configurations, could allow an elevated user to obtain SMB credentials that may be used to access vSnap data stores. IBM X-Force ID: 249325.
ModificadaMedia (5.9)0.40%—IBM Spectrum Protect Plus14/12/202217/6/2026
IBM Spectrum Protect Plus 10.1.0 through 10.1.12 discloses sensitive information due to unencrypted data being used in the communication flow between Spectrum Protect Plus vSnap and its agents. An attacker could obtain information using main in the middle techniques. IBM X-Force ID: 182106.
ModificadaAlta (7.5)1.8%—IBM Spectrum Protect Plus19/9/202217/6/2026
IBM Spectrum Protect Plus 10.1.6 through 10.1.11 Microsoft File Systems restore operation can download any file on the target machine by manipulating the URL with a directory traversal attack. This results in the restore operation gaining access to files which the operator should not have access to. IBM X-Force ID:…
ModificadaMedia (5.9)0.61%—IBM Spectrum Protect Plus19/9/202217/6/2026
Versions of IBM Spectrum Protect Plus prior to 10.1.12 (excluding 10.1.12) include the private key information for a certificate inside the generated .crt file when uploading a TLS certificate to IBM Spectrum Protect Plus. If this generated .crt file is shared, an attacker can obtain the private key information for…
ModificadaMedia (5.5)0.29%—Linux KernelIBM Spectrum Copy Data ManagementIBM Spectrum Protect PlusDebian Linux+1926/8/202217/6/2026
A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS.
ModificadaMedia (6.5)0.39%—IBM Spectrum Protect Server30/6/202217/6/2026
While a user account for the IBM Spectrum Protect Server 8.1.0.000 through 8.1.14 is being established, it may be configured to use SESSIONSECURITY=TRANSITIONAL. While in this mode, it may be susceptible to an offline dictionary attack. IBM X-Force ID: 226942.
ModificadaMedia (5.3)1.6%—IBM Spectrum Protect Operations Center30/6/202217/6/2026
IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14 could allow a remote attacker to gain details of the database, such as type and version, by sending a specially-crafted HTTP request. This information could then be used in future attacks. IBM X-Force ID: 226940.
ModificadaCrítica (9.8)1.5%—IBM Spectrum Protect Server30/6/202217/6/2026
An IBM Spectrum Protect storage agent could allow a remote attacker to perform a brute force attack by allowing unlimited attempts to login to the storage agent without locking the administrative ID. A remote attacker could exploit this vulnerability using brute force techniques to gain unauthorized administrative…
ModificadaMedia (5.5)0.16%—IBM Spectrum Protect Client30/6/202217/6/2026
IBM Spectrum Protect Client 8.1.0.0 through 8.1.14.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 225886.
ModificadaAlta (7.5)1.1%—IBM Spectrum Protect Client30/6/202217/6/2026
IBM Spectrum Protect 8.1.0.0 through 8.1.14.0 dsmcad, dsmc, and dsmcsvc processes incorrectly handle certain read operations on TCP/IP sockets. This can result in a denial of service for IBM Spectrum Protect client operations. IBM X-Force ID: 225348.
ModificadaAlta (8.8)0.89%—IBM Spectrum Protect Plus Container Backup AND Restore30/6/202217/6/2026
IBM Spectrum Protect Plus Container Backup and Restore (10.1.5 through 10.1.10.2 for Kubernetes and 10.1.7 through 10.1.10.2 for Red Hat OpenShift) could allow a remote attacker to bypass IBM Spectrum Protect Plus role based access control restrictions, caused by improper disclosure of session information. By…
ModificadaCrítica (9.8)1.1%—IBM Spectrum Protect Operations Center17/6/202217/6/2026
In some cases, an unsuccessful attempt to log into IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14.000 does not cause the administrator's invalid sign-on count to be incremented on the IBM Spectrum Protect Server. An attacker could exploit this vulnerability using brute force techniques to gain…
ModificadaAlta (7.5)0.71%—IBM Spectrum Protect Plus6/6/202217/6/2026
Credentials are printed in clear text in the IBM Spectrum Protect Plus 10.1.0.0 through 10.1.9.3 virgo log file in certain cases. Credentials could be the remote vSnap, offload targets, or VADP credentials depending on the operation performed. Credentials that are using API key or certificate are not printed. IBM…
ModificadaMedia (5.5)0.16%—IBM Spectrum Protect17/5/202217/6/2026
IBM Spectrum Protect Operations Center 8.1.12 and 8.1.13 could allow a local attacker to obtain sensitive information, caused by plain text user account passwords potentially being stored in the browser's application command history. By accessing browser history, an attacker could exploit this vulnerability to obtain…
ModificadaAlta (8.8)2.2%—IBM Spectrum Protect21/3/202217/6/2026
The IBM Spectrum Protect 8.1.14.000 server could allow a remote attacker to bypass security restrictions, caused by improper enforcement of access controls. By signing in, an attacker could exploit this vulnerability to bypass security and gain unauthorized administrator or node access to the vulnerable server.
ModificadaAlta (7.5)0.94%—IBM Spectrum Copy Data ManagementIBM Spectrum Protect Plus14/3/202217/6/2026
IBM Spectrum Protect Plus 10.1.0.0 through 10.1.9.2 and IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 do not limit the length of a connection which could allow for a Slowloris HTTP denial of service attack to take place. This can cause the Admin Console to become unresponsive. IBM X-Force ID: 220485.
ModificadaBaja (2.4)0.20%—IBM Spectrum Protect Operations Center14/3/202217/6/2026
IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.13.xxx is vulnerable to reverse tabnabbing where it could allow a page linked to from within Operations Center to rewrite it. An administrator could enter a link to a malicious URL that another administrator could then click. Once clicked, that malicious URL…
ModificadaAlta (8.8)0.38%—IBM Spectrum Protect Operations Center14/3/202217/6/2026
IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.13.xxx is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 220048.
ModificadaCrítica (9.1)0.66%—IBM Spectrum Protect Plus13/12/202117/6/2026
IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information due to a misconfiguration in access control headers. IBM X-Force ID: 214956.
ModificadaAlta (8.1)0.49%—IBM Spectrum Protect Plus13/12/202117/6/2026
IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 214616.
ModificadaMedia (5.5)0.28%—IBM Spectrum Protect Backup-archive ClientIBM Spectrum Protect FOR Space Management13/12/202117/6/2026
IBM Spectrum Protect Client 7.1 and 8.1 is vulnerable to a stack based buffer overflow, caused by improper bounds checking. A local attacker could exploit this vulnerability and cause a denial of service. IBM X-Force ID: 214438.