Ibm Mq Appliance vulnerabilities

52 known vulnerabilities affecting ibm/mq_appliance.

Total CVEs
52
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH16MEDIUM35

Vulnerabilities

Page 2 of 3
CVE-2022-22321MEDIUMCVSS 5.5v9.2 LTSv9.2 CD2022-03-01
CVE-2022-22321 [MEDIUM] CWE-326 CVE-2022-22321: IBM MQ Appliance 9.2 CD and 9.2 LTS local messaging users stored with a password hash that provides IBM MQ Appliance 9.2 CD and 9.2 LTS local messaging users stored with a password hash that provides insufficient protection. IBM X-Force ID: 218368.
cvelistv5nvd
CVE-2021-38986MEDIUMCVSS 5.4v9.2 LTSv9.2 CD2022-03-01
CVE-2021-38986 [MEDIUM] CWE-613 CVE-2021-38986: IBM MQ Appliance 9.2 CD and 9.2 LTS does not invalidate session after logout which could allow an au IBM MQ Appliance 9.2 CD and 9.2 LTS does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 212942.
cvelistv5nvd
CVE-2021-39000MEDIUMCVSS 5.5v9.2.0.0v9.2.1+5 more2021-11-30
CVE-2021-39000 [MEDIUM] CWE-200 CVE-2021-39000: IBM MQ Appliance 9.2 CD and 9.2 LTS could allow a local attacker to obtain sensitive information by IBM MQ Appliance 9.2 CD and 9.2 LTS could allow a local attacker to obtain sensitive information by inclusion of sensitive data within diagnostics. IBM X-Force ID: 213215.
cvelistv5nvd
CVE-2021-38967MEDIUMCVSS 6.7v9.2.0.0v9.2.1+5 more2021-11-30
CVE-2021-38967 [MEDIUM] CWE-94 CVE-2021-38967: IBM MQ Appliance 9.2 CD and 9.2 LTS could allow a local privileged user to inject and execute malici IBM MQ Appliance 9.2 CD and 9.2 LTS could allow a local privileged user to inject and execute malicious code. IBM X-Force ID: 212441.
cvelistv5nvd
CVE-2021-38958MEDIUMCVSS 5.5v9.2.0.0v9.2.1+5 more2021-11-30
CVE-2021-38958 [MEDIUM] CVE-2021-38958: IBM MQ Appliance 9.2 CD and 9.2 LTS is affected by a denial of service attack caused by a concurrenc IBM MQ Appliance 9.2 CD and 9.2 LTS is affected by a denial of service attack caused by a concurrency issue. IBM X-Force ID: 212042
cvelistv5nvd
CVE-2021-38999MEDIUMCVSS 5.5v9.2.0.0v9.2.1+5 more2021-11-30
CVE-2021-38999 [MEDIUM] CWE-200 CVE-2021-38999: IBM MQ Appliance could allow a local attacker to obtain sensitive information by inclusion of sensit IBM MQ Appliance could allow a local attacker to obtain sensitive information by inclusion of sensitive data within trace.
cvelistv5nvd
CVE-2021-29843MEDIUMCVSS 6.5≥ 9.1.0.0, < 9.1.0.9≥ 9.1.0.0, < 9.2.3+5 more2021-11-08
CVE-2021-29843 [MEDIUM] CVE-2021-29843: IBM MQ 9.1 LTS, 9.1 CD, 9.2 LTS, and 9.2CD is vulnerable to a denial of service attack caused by an IBM MQ 9.1 LTS, 9.1 CD, 9.2 LTS, and 9.2CD is vulnerable to a denial of service attack caused by an issue processing message properties. IBM X-Force ID: 205203.
cvelistv5nvd
CVE-2020-4938HIGHCVSS 8.8≥ 9.1, < 9.2.2≥ 9.1.0.0, < 9.1.0.8+3 more2021-07-12
CVE-2020-4938 [HIGH] CWE-352 CVE-2020-4938: IBM MQ Appliance 9.1 and 9.2 is vulnerable to cross-site request forgery which could allow an attack IBM MQ Appliance 9.1 and 9.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 191815.
cvelistv5nvd
CVE-2020-4931MEDIUMCVSS 6.5v9.1.0.0v9.1.0.1+12 more2021-02-24
CVE-2020-4931 [MEDIUM] CVE-2020-4931: IBM MQ 9.1 LTS, 9.2 LTS, and 9.1 CD AMQP Channels could allow an authenticated user to cause a denia IBM MQ 9.1 LTS, 9.2 LTS, and 9.1 CD AMQP Channels could allow an authenticated user to cause a denial of service due to an issue processing messages. IBM X-Force ID: 191747.
cvelistv5nvd
CVE-2020-4682CRITICALCVSS 9.8v9.2.0.02021-01-28
CVE-2020-4682 [CRITICAL] CWE-502 CVE-2020-4682: IBM MQ 7.5, 8.0, 9.0, 9.1, 9.2 LTS, and 9.2 CD could allow a remote attacker to execute arbitrary co IBM MQ 7.5, 8.0, 9.0, 9.1, 9.2 LTS, and 9.2 CD could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization of trusted data. An attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 186509.
nvd
CVE-2020-4869MEDIUMCVSS 6.5v9.2.0.0v9.2.12021-01-11
CVE-2020-4869 [MEDIUM] CWE-120 CVE-2020-4869: IBM MQ Appliance 9.2 CD and 9.2 LTS is vulnerable to a denial of service, caused by a buffer overflo IBM MQ Appliance 9.2 CD and 9.2 LTS is vulnerable to a denial of service, caused by a buffer overflow. A remote attacker could send a specially crafted SNMP query to cause the appliance to reload. IBM X-Force ID: 190831.
cvelistv5nvd
CVE-2020-4870HIGHCVSS 7.5v9.2.0.02020-12-21
CVE-2020-4870 [HIGH] CVE-2020-4870: IBM MQ 9.2 CD and LTS are vulnerable to a denial of service attack caused by an error processing con IBM MQ 9.2 CD and LTS are vulnerable to a denial of service attack caused by an error processing connecting applications. IBM X-Force ID: 190833.
cvelistv5nvd
CVE-2020-4592MEDIUMCVSS 6.5v9.1.0.0v9.1.LTS+1 more2020-11-18
CVE-2020-4592 [MEDIUM] CVE-2020-4592: IBM MQ Appliance 9.1.CD and LTS could allow an authenticated user, under nondefault configuration to IBM MQ Appliance 9.1.CD and LTS could allow an authenticated user, under nondefault configuration to cause a data corruption attack due to an error when using segmented messages.
cvelistv5nvd
CVE-2020-4375HIGHCVSS 7.5≥ 8.0, < 8.0.0.15≥ 9.1.0.0, < 9.1.0.6+4 more2020-07-28
CVE-2020-4375 [HIGH] CWE-401 CVE-2020-4375: IBM MQ, IBM MQ Appliance, IBM MQ for HPE NonStop 8.0, 9.1 CD, and 9.1 LTS could allow an attacker to IBM MQ, IBM MQ Appliance, IBM MQ for HPE NonStop 8.0, 9.1 CD, and 9.1 LTS could allow an attacker to cause a denial of service due to a memory leak caused by an error creating a dynamic queue. IBM X-Force ID: 179080.
cvelistv5nvd
CVE-2020-4465MEDIUMCVSS 6.5≥ 8.0, < 8.0.0.15≥ 9.1.0.0, < 9.1.0.6+4 more2020-07-28
CVE-2020-4465 [MEDIUM] CWE-120 CVE-2020-4465: IBM MQ, IBM MQ Appliance, and IBM MQ for HPE NonStop 8.0, 9.1 CD, and 9.1 LTS is vulnerable to a buf IBM MQ, IBM MQ Appliance, and IBM MQ for HPE NonStop 8.0, 9.1 CD, and 9.1 LTS is vulnerable to a buffer overflow vulnerability due to an error within the channel processing code. A remote attacker could overflow the buffer using an older client and cause a denial of service. IBM X-Force ID: 181562.
cvelistv5nvd
CVE-2020-4319MEDIUMCVSS 4.3≥ 8.0, < 8.0.0.15≥ 9.1.0.0, < 9.1.0.6+4 more2020-07-28
CVE-2020-4319 [MEDIUM] CWE-209 CVE-2020-4319: IBM MQ, IBM MQ Appliance, and IBM MQ for HPE NonStop 8.0, 9.1 LTS, and 9.1 CD could allow under spec IBM MQ, IBM MQ Appliance, and IBM MQ for HPE NonStop 8.0, 9.1 LTS, and 9.1 CD could allow under special circumstances, an authenticated user to obtain sensitive information due to a data leak from an error message within the pre-v7 pubsub logic. IBM X-Force ID: 177402.
cvelistv5nvd
CVE-2019-4731MEDIUMCVSS 5.5v9.1.4v9.1.4.CD2020-07-28
CVE-2019-4731 [MEDIUM] CWE-200 CVE-2019-4731: IBM MQ Appliance 9.1.4.CD could allow a local attacker to obtain highly sensitive information by inc IBM MQ Appliance 9.1.4.CD could allow a local attacker to obtain highly sensitive information by inclusion of sensitive data within trace. IBM X-Force ID: 172616.
cvelistv5nvd
CVE-2020-4498MEDIUMCVSS 4.4≥ 9.1.0.0, < 9.1.0.6≥ 9.1.0.0, < 9.2.0.0+11 more2020-07-27
CVE-2020-4498 [MEDIUM] CWE-532 CVE-2020-4498: IBM MQ Appliance 9.1 LTS and 9.1 CD could allow a local privileged user to obtain highly sensitve in IBM MQ Appliance 9.1 LTS and 9.1 CD could allow a local privileged user to obtain highly sensitve information due to inclusion of data within trace files. IBM X-Force ID: 182118.
cvelistv5nvd
CVE-2020-4267MEDIUMCVSS 6.5≥ 9.1.0, < 9.1.5v8.0.0.3+21 more2020-04-24
CVE-2020-4267 [MEDIUM] CWE-401 CVE-2020-4267: IBM MQ and MQ Appliance 8.0, 9.1 LTS, and 9.1 CD could allow an authenticated user cause a denial of IBM MQ and MQ Appliance 8.0, 9.1 LTS, and 9.1 CD could allow an authenticated user cause a denial of service due to a memory leak. IBM X-Force ID: 175840.
cvelistv5nvd
CVE-2019-4619MEDIUMCVSS 5.5≥ 8.0.0.0, < 8.0.0.14≥ 9.1.0, < 9.1.4+1 more2020-03-16
CVE-2019-4619 [MEDIUM] CWE-209 CVE-2019-4619: IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD could allow a local attacker IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD could allow a local attacker to obtain sensitive information by inclusion of sensitive data within trace. IBM X-Force ID: 168862.
nvd