Ibm Mq vulnerabilities
86 known vulnerabilities affecting ibm/mq.
Total CVEs
86
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH25MEDIUM56LOW3
Vulnerabilities
Page 4 of 5
CVE-2021-38949P4MEDIUMCVSS 5.5≥ 8.0.0.0, < 8.0.0.14≥ 9.0.0.0, < 9.0.0.9+6 more2021-11-16
CVE-2021-38949 [MEDIUM] CWE-312 CVE-2021-38949: IBM MQ 7.5, 8.0, 9.0 LTS, 9.1 CD, and 9.1 LTS stores user credentials in plain clear text which can
IBM MQ 7.5, 8.0, 9.0 LTS, 9.1 CD, and 9.1 LTS stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 211403.
nvd
CVE-2017-1786P4MEDIUMCVSS 5.3v8.0v9.0+14 more2018-04-23
CVE-2017-1786 [MEDIUM] CWE-772 CVE-2017-1786: IBM WebSphere MQ 8.0 through 8.0.0.8 and 9.0 through 9.0.4 under special circumstances could allow a
IBM WebSphere MQ 8.0 through 8.0.0.8 and 9.0 through 9.0.4 under special circumstances could allow an authenticated user to consume all resources due to a memory leak resulting in service loss. IBM X-Force ID: 136975.
nvd
CVE-2020-4338P4MEDIUMCVSS 5.5≥ 9.1.0, < 9.1.5v9.1.42020-04-16
CVE-2020-4338 [MEDIUM] CWE-200 CVE-2020-4338: IBM MQ 9.1.4 could allow a local attacker to obtain sensitive information by inclusion of sensitive
IBM MQ 9.1.4 could allow a local attacker to obtain sensitive information by inclusion of sensitive data within runmqras data. IBM X-Force ID: 177937.
nvd
CVE-2019-4619P4MEDIUMCVSS 5.5≥ 8.0.0.0, < 8.0.0.14≥ 9.0.0.0, ≤ 9.0.0.9+52 more2020-03-16
CVE-2019-4619 [MEDIUM] CWE-209 CVE-2019-4619: IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD could allow a local attacker
IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD could allow a local attacker to obtain sensitive information by inclusion of sensitive data within trace. IBM X-Force ID: 168862.
nvd
CVE-2019-4719P4MEDIUMCVSS 5.5≥ 8.0.0.0, < 8.0.0.14≥ 9.0.0.0, ≤ 9.0.0.9+52 more2020-03-16
CVE-2019-4719 [MEDIUM] CVE-2019-4719: IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD could allow a local attacker
IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD could allow a local attacker to obtain sensitive information by inclusion of sensitive data within runmqras data.
nvd
CVE-2016-6089P4MEDIUMCVSS 5.5v9.0.0.1v9.0.22017-06-07
CVE-2016-6089 [MEDIUM] CWE-284 CVE-2016-6089: IBM WebSphere MQ 9.0.0.1 and 9.0.2 could allow a local user to write to a file or delete files in a
IBM WebSphere MQ 9.0.0.1 and 9.0.2 could allow a local user to write to a file or delete files in a directory they should not have access to due to improper access controls. IBM X-Force ID: 117926.
nvd
CVE-2025-0985P4MEDIUMCVSS 5.5v9.3.0v9.4.0+1 more2025-02-28
CVE-2025-0985 [MEDIUM] CWE-526 CVE-2025-0985: IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD stores potentially sensitive information in environmen
IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD
stores potentially sensitive information in environment variables that could be obtained by a local user.
nvd
CVE-2022-22321P4MEDIUMCVSS 5.5≥ 9.2.0, < 9.2.0.5≥ 9.2.0, < 9.2.52022-03-01
CVE-2022-22321 [MEDIUM] CWE-326 CVE-2022-22321: IBM MQ Appliance 9.2 CD and 9.2 LTS local messaging users stored with a password hash that provides
IBM MQ Appliance 9.2 CD and 9.2 LTS local messaging users stored with a password hash that provides insufficient protection. IBM X-Force ID: 218368.
nvd
CVE-2023-45177P4MEDIUMCVSS 5.3≥ 9.0.0.0, < 9.0.0.21≥ 9.1.0.0, < 9.1.0.18+4 more2024-03-20
CVE-2023-45177 [MEDIUM] CWE-20 CVE-2023-45177: IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS and 9.3 CD is vulnerable to a denial-of-service attack due
IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS and 9.3 CD is vulnerable to a denial-of-service attack due to an error within the MQ clustering logic. IBM X-Force ID: 268066.
nvd
CVE-2017-1117P4MEDIUMCVSS 5.3v8.0v9.0+6 more2017-06-21
CVE-2017-1117 [MEDIUM] CVE-2017-1117: IBM WebSphere MQ 8.0 and 9.0 could allow an authenticated user to cause a denial of service to the M
IBM WebSphere MQ 8.0 and 9.0 could allow an authenticated user to cause a denial of service to the MQXR channel when trace is enabled. IBM X-Force ID: 121155.
nvd
CVE-2026-1713P4MEDIUMCVSS 5.0≥ 9.1.0.0, < 9.1.0.34≥ 9.2.0.0, < 9.2.0.41+8 more2026-03-03
CVE-2026-1713 [MEDIUM] CWE-305 CVE-2026-1713: IBM MQ 9.1.0.0 through 9.1.0.33 LTS, 9.2.0.0 through 9.2.0.40 LTS, 9.3.0.0 through 9.3.0.36 LTS, 9.3
IBM MQ 9.1.0.0 through 9.1.0.33 LTS, 9.2.0.0 through 9.2.0.40 LTS, 9.3.0.0 through 9.3.0.36 LTS, 9.30.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.17 LTS, and 9.4.0.0 through 9.4.4.1 CD
nvd
CVE-2024-52898P4MEDIUMCVSS 6.2≥ 9.3.0, ≤ 9.4.1.1≥ 9.3.0.0, ≤ 9.3.0.26+2 more2025-01-14
CVE-2024-52898 [MEDIUM] CWE-209 CVE-2024-52898: IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a local user to obtain sensitive
IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a local user to obtain sensitive information when a detailed technical error message is returned.
nvd
CVE-2023-28514P4MEDIUMCVSS 5.5v8.0.0.0v9.0.0.0+3 more2023-05-19
CVE-2023-28514 [MEDIUM] CWE-209 CVE-2023-28514: IBM MQ 8.0, 9.0, and 9.1 could allow a local user to obtain sensitive credential information when a
IBM MQ 8.0, 9.0, and 9.1 could allow a local user to obtain sensitive credential information when a detailed technical error message is returned in a stack trace. IBM X-Force ID: 250398.
nvd
CVE-2017-1557P4MEDIUMCVSS 4.3v8.0v9.0+11 more2018-01-02
CVE-2017-1557 [MEDIUM] CVE-2017-1557: IBM WebSphere MQ 8.0 and 9.0 could allow an authenticated user with authority to send a specially cr
IBM WebSphere MQ 8.0 and 9.0 could allow an authenticated user with authority to send a specially crafted request that could cause a channel process to cease processing further requests. IBM X-Force ID: 131547.
nvd
CVE-2024-54173P4MEDIUMCVSS 4.7v9.3 LTS, 9.3 CD, 9.4 LTS, 9.4 CD2025-02-28
CVE-2024-54173 [MEDIUM] CWE-1323 CVE-2024-54173: IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD reveals potentially sensitive information in trace files
IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD reveals potentially sensitive information in trace files that could be read by a local user when webconsole trace is enabled.
nvd
CVE-2017-1284P4MEDIUMCVSS 4.7v9.0.1v9.0.22017-07-10
CVE-2017-1284 [MEDIUM] CWE-200 CVE-2017-1284: IBM WebSphere MQ 9.0.1 and 9.0.2 could allow a local user with ability to run or enable trace, to ob
IBM WebSphere MQ 9.0.1 and 9.0.2 could allow a local user with ability to run or enable trace, to obtain sensitive information from WebSphere Application Server traces including user credentials. IBM X-Force ID: 125145.
nvd
CVE-2019-4655P4MEDIUMCVSS 4.3≥ 9.1.0, < 9.1.4≥ 9.1.0.0, < 9.1.0.4+7 more2019-12-30
CVE-2019-4655 [MEDIUM] CVE-2019-4655: IBM MQ 9.1.0.0, 9.1.0.1, 9.1.0.2, 9.1.0.3, 9.1.1, 9.1.2, and 9.1.3 is vulnerable to a denial of serv
IBM MQ 9.1.0.0, 9.1.0.1, 9.1.0.2, 9.1.0.3, 9.1.1, 9.1.2, and 9.1.3 is vulnerable to a denial of service attack that would allow an authenticated user to reset client connections due to an error within the Data Conversion routine. IBM X-Force ID: 170966.
nvd
CVE-2017-1283P4MEDIUMCVSS 4.3v8.0v9.0+12 more2017-11-27
CVE-2017-1283 [MEDIUM] CWE-772 CVE-2017-1283: IBM WebSphere MQ 8.0 and 9.0 could allow an authenticated user to cause a shared memory leak by MQ a
IBM WebSphere MQ 8.0 and 9.0 could allow an authenticated user to cause a shared memory leak by MQ applications using dynamic queues, which can lead to lack of resources for other MQ applications. IBM X-Force ID: 125144.
nvd
CVE-2019-4049P4MEDIUMCVSS 5.5≥ 9.1.0, ≤ 9.1.1≥ 9.1.0.0, ≤ 9.1.0.2+4 more2019-08-20
CVE-2019-4049 [MEDIUM] CWE-400 CVE-2019-4049: IBM MQ 9.1.0.0, 9.1.0.1, 9.1.1, and 9.1.0.2 is vulnerable to a denial of service due to a local user
IBM MQ 9.1.0.0, 9.1.0.1, 9.1.1, and 9.1.0.2 is vulnerable to a denial of service due to a local user being able to fill up the disk space of the underlying filesystem using the error logging service. IBM X-Force ID: 156398.
nvd
CVE-2023-22874P4MEDIUMCVSS 5.5v9.2 CD, 9.3 CD, and 9.3 LTS2023-05-05
CVE-2023-22874 [MEDIUM] CWE-400 CVE-2023-22874: IBM MQ Clients 9.2 CD, 9.3 CD, and 9.3 LTS are vulnerable to a denial of service attack when process
IBM MQ Clients 9.2 CD, 9.3 CD, and 9.3 LTS are vulnerable to a denial of service attack when processing configuration files. IBM X-Force ID: 244216.
nvd