cbcvebase.

Ibm Integration Bus vulnerabilities

24 known vulnerabilities affecting ibm/integration_bus.

Total CVEs
24
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM18LOW4

Vulnerabilities

Page 2 of 2
CVE-2015-2018P4LOWCVSS 3.5v9.0v10.02015-08-23
CVE-2015-2018 [LOW] CWE-200 CVE-2015-2018: IBM Integration Bus 9 and 10 before 10.0.0.1 and WebSphere Message Broker 7 before 7.0.0.8 and 8 bef IBM Integration Bus 9 and 10 before 10.0.0.1 and WebSphere Message Broker 7 before 7.0.0.8 and 8 before 8.0.0.7 do not ensure that the correct security profile is selected, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
nvd
CVE-2016-0394P4LOWCVSS 3.3v9.0v9.0.0.1+2 more2017-02-01
CVE-2016-0394 [LOW] CWE-275 CVE-2016-0394: IBM Integration Bus and WebSphere Message broker sets incorrect permissions for an object that could IBM Integration Bus and WebSphere Message broker sets incorrect permissions for an object that could allow a local attacker to manipulate certain files.
nvd
CVE-2015-5011P4LOWCVSS 3.2v9.0v9.0.0.1+2 more2015-10-26
CVE-2015-5011 [LOW] CWE-77 CVE-2015-5011: IBM WebSphere Message Broker 8 before 8.0.0.6 and Integration Bus 9 before 9.0.0.4 do not check auth IBM WebSphere Message Broker 8 before 8.0.0.6 and Integration Bus 9 before 9.0.0.4 do not check authorization for MQSISTARTMSGFLOW and MQSISTOPMSGFLOW commands, which allows local users to bypass intended access restrictions, and start or stop a service, by issuing a command.
nvd
CVE-2017-1144P4LOWCVSS 2.5v9.0v9.0.0.1+14 more2017-07-05
CVE-2017-1144 [LOW] CWE-426 CVE-2017-1144: IBM WebSphere Message Broker could allow a local user with specialized access to prevent the message IBM WebSphere Message Broker could allow a local user with specialized access to prevent the message broker from starting. IBM X-Force ID: 122033.
nvd