cbcvebase.

Ibm Mq Appliance vulnerabilities

52 known vulnerabilities affecting ibm/mq_appliance.

Total CVEs
52
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH16MEDIUM35

Vulnerabilities

Page 1 of 3
CVE-2020-4682P2CRITICALCVSS 9.8v9.2.0.02021-01-28
CVE-2020-4682 [CRITICAL] CWE-502 CVE-2020-4682: IBM MQ 7.5, 8.0, 9.0, 9.1, 9.2 LTS, and 9.2 CD could allow a remote attacker to execute arbitrary co IBM MQ 7.5, 8.0, 9.0, 9.1, 9.2 LTS, and 9.2 CD could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization of trusted data. An attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 186509.
nvd
CVE-2017-1318P3HIGHCVSS 8.8v8.0.0.0v8.0.0.1+8 more2017-07-18
CVE-2017-1318 [HIGH] CWE-78 CVE-2017-1318: IBM MQ Appliance 8.0 and 9.0 could allow an authenticated messaging administrator to execute arbitra IBM MQ Appliance 8.0 and 9.0 could allow an authenticated messaging administrator to execute arbitrary commands on the system, caused by command execution. IBM X-Force ID: 125730.
nvd
CVE-2025-0975P3HIGHCVSS 8.8≥ 9.3.0, ≤ 9.4.2≥ 9.3.0.0, ≤ 9.3.0.27+1 more2025-02-28
CVE-2025-0975 [HIGH] CWE-150 CVE-2025-0975: IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD console could allow an authenticated user to execute cod IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD console could allow an authenticated user to execute code due to improper neutralization of escape characters.
nvd
CVE-2023-46177P3HIGHCVSS 7.5v9.3.0.0v9.3 LTS, 9.3 CD2023-12-18
CVE-2023-46177 [HIGH] CWE-22 CVE-2023-46177: IBM MQ Appliance 9.3 LTS and 9.3 CD could allow a remote attacker to traverse directories on the sys IBM MQ Appliance 9.3 LTS and 9.3 CD could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request to view arbitrary files on the system. IBM X-Force ID: 269536.
nvd
CVE-2024-25048P3HIGHCVSS 7.5≥ 9.3.0.0, < 9.3.0.17≥ 9.3.0.0, < 9.3.5+1 more2024-04-27
CVE-2024-25048 [HIGH] CWE-122 CVE-2024-25048: IBM MQ Appliance 9.3 CD and LTS are vulnerable to a heap-based buffer overflow, caused by improper b IBM MQ Appliance 9.3 CD and LTS are vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote authenticated attacker could overflow a buffer and execute arbitrary code on the system or cause the server to crash. IBM X-Force ID: 283137.
nvd
CVE-2019-4294P3HIGHCVSS 7.8≥ 8.0.0.0, ≤ 8.0.0.12≥ 9.1.0.0, ≤ 9.1.0.2+19 more2019-08-20
CVE-2019-4294 [HIGH] CWE-78 CVE-2019-4294: IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.6, 7.6.0.0 through 7.6.0.15 and IBM MQ Appliance 8 IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.6, 7.6.0.0 through 7.6.0.15 and IBM MQ Appliance 8.0.0.0 through 8.0.0.12, 9.1.0.0 through 9.1.0.2, and 9.1.1 through 9.1.2 could allow a local attacker to execute arbitrary commands on the system, caused by a command injection vulnerability. IBM X-Force ID: 16188.
nvd
CVE-2024-25016P3HIGHCVSS 7.5≥ 9.3.0.0, ≤ 9.3.5.02024-03-03
CVE-2024-25016 [HIGH] CWE-20 CVE-2024-25016: IBM MQ and IBM MQ Appliance 9.0, 9.1, 9.2, 9.3 LTS and 9.3 CD could allow a remote unauthenticated a IBM MQ and IBM MQ Appliance 9.0, 9.1, 9.2, 9.3 LTS and 9.3 CD could allow a remote unauthenticated attacker to cause a denial of service due to incorrect buffering logic. IBM X-Force ID: 281279.
nvd
CVE-2025-3631P3HIGHCVSS 7.5≥ 9.3.2, ≤ 9.3.5.2≥ 9.4.0.0, < 9.4.0.12+5 more2025-07-11
CVE-2025-3631 [HIGH] CWE-416 CVE-2025-3631: An IBM MQ 9.3 and 9.4 Client connecting to an MQ Queue Manager can cause a SIGSEGV in the AMQRMPPA c An IBM MQ 9.3 and 9.4 Client connecting to an MQ Queue Manager can cause a SIGSEGV in the AMQRMPPA channel process terminating it.
nvd
CVE-2023-46176P3HIGHCVSS 7.8v9.3.0.0v9.3 CD2023-11-03
CVE-2023-46176 [HIGH] CWE-424 CVE-2023-46176: IBM MQ Appliance 9.3 CD could allow a local attacker to gain elevated privileges on the system, caus IBM MQ Appliance 9.3 CD could allow a local attacker to gain elevated privileges on the system, caused by improper validation of security keys. IBM X-Force ID: 269535.
nvd
CVE-2020-4938P3HIGHCVSS 8.8≥ 9.1, < 9.2.2≥ 9.1.0.0, < 9.1.0.8+3 more2021-07-12
CVE-2020-4938 [HIGH] CWE-352 CVE-2020-4938: IBM MQ Appliance 9.1 and 9.2 is vulnerable to cross-site request forgery which could allow an attack IBM MQ Appliance 9.1 and 9.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 191815.
nvd
CVE-2019-4055P3HIGHCVSS 7.5≥ 8.0.0.0, ≤ 8.0.0.10≥ 9.1.0, ≤ 9.1.1+1 more2019-04-19
CVE-2019-4055 [HIGH] CVE-2019-4055: IBM MQ 8.0.0.0 through 8.0.0.10, 9.0.0.0 through 9.0.0.5, and 9.1.0.0 through 9.1.1 is vulnerable to IBM MQ 8.0.0.0 through 8.0.0.10, 9.0.0.0 through 9.0.0.5, and 9.1.0.0 through 9.1.1 is vulnerable to a denial of service attack within the TLS key renegotiation function. IBM X-Force ID: 156564.
nvd
CVE-2020-4870P3HIGHCVSS 7.5v9.2.0.02020-12-21
CVE-2020-4870 [HIGH] CVE-2020-4870: IBM MQ 9.2 CD and LTS are vulnerable to a denial of service attack caused by an error processing con IBM MQ 9.2 CD and LTS are vulnerable to a denial of service attack caused by an error processing connecting applications. IBM X-Force ID: 190833.
nvd
CVE-2019-4620P3HIGHCVSS 7.8≥ 8.0.0.0, < 8.0.0.14≥ 9.1.0, < 9.1.4+20 more2020-01-28
CVE-2019-4620 [HIGH] CWE-20 CVE-2019-4620: IBM MQ Appliance 8.0 and 9.0 LTS could allow a local attacker to bypass security restrictions caused IBM MQ Appliance 8.0 and 9.0 LTS could allow a local attacker to bypass security restrictions caused by improper validation of environment variables. IBM X-Force ID: 168863.
nvd
CVE-2023-28513P3HIGHCVSS 7.5v9.2.0.0v9.3.0.0+1 more2023-07-19
CVE-2023-28513 [HIGH] CWE-20 CVE-2023-28513: IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.2 CD, and 9.3 CD and IBM MQ Appliance 9.2 LTS, 9.3 LTS, IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.2 CD, and 9.3 CD and IBM MQ Appliance 9.2 LTS, 9.3 LTS, 9.2 CD, and 9.2 LTS, under certain configurations, is vulnerable to a denial of service attack caused by an error processing messages. IBM X-Force ID: 250397.
nvd
CVE-2022-43902P3HIGHCVSS 7.5≥ 9.2.0.0, < 9.2.0.8≥ 9.2.0.0, < 9.2.5+3 more2023-03-10
CVE-2022-43902 [HIGH] CVE-2022-43902: IBM MQ 9.2 CD, 9.2 LTS, 9.3 CD, and 9.3 LTS is vulnerable to a denial of service attack caused by sp IBM MQ 9.2 CD, 9.2 LTS, 9.3 CD, and 9.3 LTS is vulnerable to a denial of service attack caused by specially crafted PCF or MQSC messages. IBM X-Force ID: 240832.
nvd
CVE-2020-4375P4HIGHCVSS 7.5≥ 8.0, < 8.0.0.15≥ 9.1.0.0, < 9.1.0.6+4 more2020-07-28
CVE-2020-4375 [HIGH] CWE-401 CVE-2020-4375: IBM MQ, IBM MQ Appliance, IBM MQ for HPE NonStop 8.0, 9.1 CD, and 9.1 LTS could allow an attacker to IBM MQ, IBM MQ Appliance, IBM MQ for HPE NonStop 8.0, 9.1 CD, and 9.1 LTS could allow an attacker to cause a denial of service due to a memory leak caused by an error creating a dynamic queue. IBM X-Force ID: 179080.
nvd
CVE-2023-26285P4HIGHCVSS 7.5≥ 9.2.0.0, < 9.2.0.11≥ 9.2.0.0, < 9.2.5.7+2 more2023-05-05
CVE-2023-26285 [HIGH] CWE-119 CVE-2023-26285: IBM MQ 9.2 CD, 9.2 LTS, 9.3 CD, and 9.3 LTS could allow a remote attacker to cause a denial of servi IBM MQ 9.2 CD, 9.2 LTS, 9.3 CD, and 9.3 LTS could allow a remote attacker to cause a denial of service due to an error processing invalid data. IBM X-Force ID: 248418.
nvd
CVE-2020-4869P4MEDIUMCVSS 6.5v9.2.0.0v9.2.12021-01-11
CVE-2020-4869 [MEDIUM] CWE-120 CVE-2020-4869: IBM MQ Appliance 9.2 CD and 9.2 LTS is vulnerable to a denial of service, caused by a buffer overflo IBM MQ Appliance 9.2 CD and 9.2 LTS is vulnerable to a denial of service, caused by a buffer overflow. A remote attacker could send a specially crafted SNMP query to cause the appliance to reload. IBM X-Force ID: 190831.
nvd
CVE-2022-22356P4MEDIUMCVSS 6.5v9.2.0.0v9.2 LTS+1 more2022-04-05
CVE-2022-22356 [MEDIUM] CWE-203 CVE-2022-22356: IBM MQ Appliance 9.2 CD and 9.2 LTS could allow an attacker to enumerate account credentials due to IBM MQ Appliance 9.2 CD and 9.2 LTS could allow an attacker to enumerate account credentials due to an observable discrepancy in valid and invalid login attempts. IBM X-Force ID: 220487.
nvd
CVE-2020-4592P4MEDIUMCVSS 6.5v9.1.0.0v9.1.LTS+1 more2020-11-18
CVE-2020-4592 [MEDIUM] CVE-2020-4592: IBM MQ Appliance 9.1.CD and LTS could allow an authenticated user, under nondefault configuration to IBM MQ Appliance 9.1.CD and LTS could allow an authenticated user, under nondefault configuration to cause a data corruption attack due to an error when using segmented messages.
nvd
Ibm Mq Appliance vulnerabilities | cvebase