Ibm Mq vulnerabilities
86 known vulnerabilities affecting ibm/mq.
Total CVEs
86
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH25MEDIUM56LOW3
Vulnerabilities
Page 1 of 5
CVE-2020-4682P2CRITICALCVSS 9.8v8.0.0.0v8.0.0.1+39 more2021-01-28
CVE-2020-4682 [CRITICAL] CWE-502 CVE-2020-4682: IBM MQ 7.5, 8.0, 9.0, 9.1, 9.2 LTS, and 9.2 CD could allow a remote attacker to execute arbitrary co
IBM MQ 7.5, 8.0, 9.0, 9.1, 9.2 LTS, and 9.2 CD could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization of trusted data. An attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 186509.
nvd
CVE-2024-40681P3HIGHCVSS 8.8v9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, 9.4 CD2024-09-07
CVE-2024-40681 [HIGH] CWE-266 CVE-2024-40681: IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow an authenticated user in a
IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow an authenticated user in a specifically defined role, to bypass security restrictions and execute actions against the queue manager.
nvd
CVE-2022-22489P3CRITICALCVSS 9.1v8.0.0.0v9.0.0.0+8 more2022-08-19
CVE-2022-22489 [CRITICAL] CWE-611 CVE-2022-22489: IBM MQ 8.0, (9.0, 9.1, 9.2 LTS), and (9.1 and 9.2 CD) are vulnerable to an XML External Entity Injec
IBM MQ 8.0, (9.0, 9.1, 9.2 LTS), and (9.1 and 9.2 CD) are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 226339.
nvd
CVE-2025-0975P3HIGHCVSS 8.8v9.3 LTS, 9.3 CD, 9.4 LTS, 9.4 CD2025-02-28
CVE-2025-0975 [HIGH] CWE-150 CVE-2025-0975: IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD console could allow an authenticated user to execute cod
IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD console could allow an authenticated user to execute code due to improper neutralization of escape characters.
nvd
CVE-2024-31912P3HIGHCVSS 8.8v9.3.0v9.3 LTS and 9.3 CD2024-06-28
CVE-2024-31912 [HIGH] CWE-266 CVE-2024-31912: IBM MQ 9.3 LTS and 9.3 CD could allow an authenticated user to escalate their privileges under certa
IBM MQ 9.3 LTS and 9.3 CD could allow an authenticated user to escalate their privileges under certain configurations due to incorrect privilege assignment. IBM X-Force ID: 289894.
nvd
CVE-2018-1974P3HIGHCVSS 7.5v9.0.0.1v8.0.0.1+18 more2019-03-11
CVE-2018-1974 [HIGH] CVE-2018-1974: IBM WebSphere 8.0.0.0 through 9.1.1 could allow an authenticated attacker to escalate their privileg
IBM WebSphere 8.0.0.0 through 9.1.1 could allow an authenticated attacker to escalate their privileges when using multiplexed channels. IBM X-Force ID: 153915.
nvd
CVE-2024-25016P3HIGHCVSS 7.5≥ 9.0.0.0, < 9.0.0.23≥ 9.1.0.0, < 9.1.0.20+3 more2024-03-03
CVE-2024-25016 [HIGH] CWE-20 CVE-2024-25016: IBM MQ and IBM MQ Appliance 9.0, 9.1, 9.2, 9.3 LTS and 9.3 CD could allow a remote unauthenticated a
IBM MQ and IBM MQ Appliance 9.0, 9.1, 9.2, 9.3 LTS and 9.3 CD could allow a remote unauthenticated attacker to cause a denial of service due to incorrect buffering logic. IBM X-Force ID: 281279.
nvd
CVE-2025-3631P3HIGHCVSS 7.5≥ 9.3.2.0 CD, ≤ 9.3.5.1 CD≥ 9.4.0.0, ≤ 9.4.2.1 CD+1 more2025-07-11
CVE-2025-3631 [HIGH] CWE-416 CVE-2025-3631: An IBM MQ 9.3 and 9.4 Client connecting to an MQ Queue Manager can cause a SIGSEGV in the AMQRMPPA c
An IBM MQ 9.3 and 9.4 Client connecting to an MQ Queue Manager can cause a SIGSEGV in the AMQRMPPA channel process terminating it.
nvd
CVE-2017-1337P3HIGHCVSS 8.1v9.0.1v9.0.22017-07-10
CVE-2017-1337 [HIGH] CWE-522 CVE-2017-1337: IBM WebSphere MQ 9.0.1 and 9.0.2 Java/JMS application can incorrectly transmit user credentials in p
IBM WebSphere MQ 9.0.1 and 9.0.2 Java/JMS application can incorrectly transmit user credentials in plain text. IBM X-Force ID: 126245.
nvd
CVE-2018-1883P3HIGHCVSS 7.5≥ 9.0.2, ≤ 9.0.5v9.1.0.0+4 more2018-12-07
CVE-2018-1883 [HIGH] CVE-2018-1883: A problem within the IBM MQ 9.0.2, 9.0.3, 9.0.4, 9.0.5, and 9.1.0.0 Console REST API Could allow att
A problem within the IBM MQ 9.0.2, 9.0.3, 9.0.4, 9.0.5, and 9.1.0.0 Console REST API Could allow attackers to execute a denial of service attack preventing users from logging into the MQ Console REST API. IBM X-Force ID: 151969.
nvd
CVE-2018-1792P3HIGHCVSS 7.8v9.0.0.1v8.0.0.1+16 more2018-11-13
CVE-2018-1792 [HIGH] CWE-94 CVE-2018-1792: IBM WebSphere MQ 8.0.0.0 through 8.0.0.10, 9.0.0.0 through 9.0.0.5, 9.0.1 through 9.0.5, and 9.1.0.0
IBM WebSphere MQ 8.0.0.0 through 8.0.0.10, 9.0.0.0 through 9.0.0.5, 9.0.1 through 9.0.5, and 9.1.0.0 could allow a local user to inject code that could be executed with root privileges. IBM X-Force ID: 148947.
nvd
CVE-2025-36128P3HIGHCVSS 7.5v9.1.0.0v9.2.0.0+8 more2025-10-16
CVE-2025-36128 [HIGH] CWE-772 CVE-2025-36128: IBM MQ 9.1, 9.2, 9.3, 9.4 LTS and 9.3, 9.4 CD is vulnerable to a denial of service, caused by improp
IBM MQ 9.1, 9.2, 9.3, 9.4 LTS and 9.3, 9.4 CD is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations. By conducting slowloris-type attacks, a remote attacker could exploit this vulnerability to cause a denial of service.
nvd
CVE-2019-4078P3HIGHCVSS 7.8v9.0.0.1v8.0.0.1+19 more2019-05-23
CVE-2019-4078 [HIGH] CWE-732 CVE-2019-4078: IBM WebSphere MQ 8.0.0.0 through 8.0.0.9 and 9.0.0.0 through 9.1.1 could allow a local non privilege
IBM WebSphere MQ 8.0.0.0 through 8.0.0.9 and 9.0.0.0 through 9.1.1 could allow a local non privileged user to execute code as an administrator due to incorrect permissions set on MQ installation directories. IBM X-Force ID: 157190.
nvd
CVE-2024-25015P3HIGHCVSS 7.5≥ 9.2.0.0, < 9.2.0.25≥ 9.3.0, < 9.3.5+2 more2024-05-01
CVE-2024-25015 [HIGH] CWE-406 CVE-2024-25015: IBM MQ 9.2 LTS, 9.3 LTS, and 9.3 CD Internet Pass-Thru could allow a remote user to cause a denial o
IBM MQ 9.2 LTS, 9.3 LTS, and 9.3 CD Internet Pass-Thru could allow a remote user to cause a denial of service by sending HTTP requests that would consume all available resources. IBM X-Force ID: 281278.
nvd
CVE-2024-35116P3HIGHCVSS 7.5≥ 9.0.0.0, < 9.0.0.26≥ 9.1.0.0, < 9.1.0.22+4 more2024-06-28
CVE-2024-35116 [HIGH] CWE-789 CVE-2024-35116: IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS, and 9.3 CD is vulnerable to a denial of service attack ca
IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS, and 9.3 CD is vulnerable to a denial of service attack caused by an error applying configuration changes. IBM X-Force ID: 290335.
nvd
CVE-2019-4227P3HIGHCVSS 7.3≥ 8.0.0.4, ≤ 8.0.0.12≥ 9.0.0.0, ≤ 9.0.0.6+23 more2019-10-04
CVE-2019-4227 [HIGH] CWE-384 CVE-2019-4227: IBM MQ 8.0.0.4 - 8.0.0.12, 9.0.0.0 - 9.0.0.6, 9.1.0.0 - 9.1.0.2, and 9.1.0 - 9.1.2 AMQP Listeners co
IBM MQ 8.0.0.4 - 8.0.0.12, 9.0.0.0 - 9.0.0.6, 9.1.0.0 - 9.1.0.2, and 9.1.0 - 9.1.2 AMQP Listeners could allow an unauthorized user to conduct a session fixation attack due to clients not being disconnected as they should. IBM X-Force ID: 159352.
nvd
CVE-2024-31919P3HIGHCVSS 7.5v9.0.0.0v9.1.0.0+3 more2024-06-28
CVE-2024-31919 [HIGH] CWE-770 CVE-2024-31919: IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS and 9.3 CD, in certain configurations, is vulnerable to a
IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS and 9.3 CD, in certain configurations, is vulnerable to a denial of service attack caused by an error processing messages when an API Exit using MQBUFMH is used. IBM X-Force ID: 290259.
nvd
CVE-2019-4055P3HIGHCVSS 7.5≥ 8.0.0.0, ≤ 8.0.0.10≥ 9.0.0.0, ≤ 9.0.0.5+22 more2019-04-19
CVE-2019-4055 [HIGH] CVE-2019-4055: IBM MQ 8.0.0.0 through 8.0.0.10, 9.0.0.0 through 9.0.0.5, and 9.1.0.0 through 9.1.1 is vulnerable to
IBM MQ 8.0.0.0 through 8.0.0.10, 9.0.0.0 through 9.0.0.5, and 9.1.0.0 through 9.1.1 is vulnerable to a denial of service attack within the TLS key renegotiation function. IBM X-Force ID: 156564.
nvd
CVE-2020-4870P3HIGHCVSS 7.5v9.2.02020-12-21
CVE-2020-4870 [HIGH] CVE-2020-4870: IBM MQ 9.2 CD and LTS are vulnerable to a denial of service attack caused by an error processing con
IBM MQ 9.2 CD and LTS are vulnerable to a denial of service attack caused by an error processing connecting applications. IBM X-Force ID: 190833.
nvd
CVE-2017-1612P3HIGHCVSS 7.8v7.0.1v7.1+3 more2018-01-09
CVE-2017-1612 [HIGH] CVE-2017-1612: IBM WebSphere MQ 7.0, 7.1, 7.5, 8.0, and 9.0 service trace module could be used to execute untrusted
IBM WebSphere MQ 7.0, 7.1, 7.5, 8.0, and 9.0 service trace module could be used to execute untrusted code under 'mqm' user. IBM X-Force ID: 132953.
nvd
1 / 5Next →