cbcvebase.

Ibm Mq Appliance vulnerabilities

52 known vulnerabilities affecting ibm/mq_appliance.

Total CVEs
52
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH16MEDIUM35

Vulnerabilities

Page 3 of 3
CVE-2022-22321P4MEDIUMCVSS 5.5v9.2 LTSv9.2 CD2022-03-01
CVE-2022-22321 [MEDIUM] CWE-326 CVE-2022-22321: IBM MQ Appliance 9.2 CD and 9.2 LTS local messaging users stored with a password hash that provides IBM MQ Appliance 9.2 CD and 9.2 LTS local messaging users stored with a password hash that provides insufficient protection. IBM X-Force ID: 218368.
nvd
CVE-2024-51471P4MEDIUMCVSS 5.3≥ 9.3.0.0, ≤ 9.3.0.26≥ 9.3.0.0, ≤ 9.4.0.7+2 more2024-12-19
CVE-2024-51471 [MEDIUM] CWE-125 CVE-2024-51471: IBM MQ Appliance 9.3 LTS, 9.3 CD, and 9.4 LTS web console could allow an authenticated user to cause IBM MQ Appliance 9.3 LTS, 9.3 CD, and 9.4 LTS web console could allow an authenticated user to cause a denial-of-service when trace is enabled due to information being written into memory outside of the intended buffer size.
nvd
CVE-2019-4731P4MEDIUMCVSS 5.5v9.1.4v9.1.4.CD2020-07-28
CVE-2019-4731 [MEDIUM] CWE-200 CVE-2019-4731: IBM MQ Appliance 9.1.4.CD could allow a local attacker to obtain highly sensitive information by inc IBM MQ Appliance 9.1.4.CD could allow a local attacker to obtain highly sensitive information by inclusion of sensitive data within trace. IBM X-Force ID: 172616.
nvd
CVE-2021-38999P4MEDIUMCVSS 5.5v9.2.0.0v9.2.1+5 more2021-11-30
CVE-2021-38999 [MEDIUM] CWE-200 CVE-2021-38999: IBM MQ Appliance could allow a local attacker to obtain sensitive information by inclusion of sensit IBM MQ Appliance could allow a local attacker to obtain sensitive information by inclusion of sensitive data within trace.
nvd
CVE-2022-22355P4MEDIUMCVSS 5.3v9.2.0.0v9.2 LTS+1 more2022-04-05
CVE-2022-22355 [MEDIUM] CVE-2022-22355: IBM MQ Appliance 9.2 CD and 9.2 LTS are vulnerable to a denial of service in the Login component of IBM MQ Appliance 9.2 CD and 9.2 LTS are vulnerable to a denial of service in the Login component of the application which could allow an attacker to cause a drop in performance.
nvd
CVE-2024-54173P4MEDIUMCVSS 4.7fixed in 9.4.2≥ 9.3.0.0, < 9.3.0.27+1 more2025-02-28
CVE-2024-54173 [MEDIUM] CWE-1323 CVE-2024-54173: IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD reveals potentially sensitive information in trace files IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD reveals potentially sensitive information in trace files that could be read by a local user when webconsole trace is enabled.
nvd
CVE-2018-1652P4MEDIUMCVSS 5.5≥ 8.0.0.0, ≤ 8.0.0.8≥ 9.0.1, ≤ 9.0.5+4 more2018-12-11
CVE-2018-1652 [MEDIUM] CWE-20 CVE-2018-1652: IBM DataPower Gateway 7.1.0.0 through 7.1.0.19, 7.2.0.0 through 7.2.0.16, 7.5.0.0 through 7.5.0.10, IBM DataPower Gateway 7.1.0.0 through 7.1.0.19, 7.2.0.0 through 7.2.0.16, 7.5.0.0 through 7.5.0.10, 7.5.1.0 through 7.5.1.9, 7.5.2.0 through 7.5.2.9, and 7.6.0.0 through 7.6.0.2 and IBM MQ Appliance 8.0.0.0 through 8.0.0.8 and 9.0.1 through 9.0.5 could allow a local user to cause a denial of service through unknown vectors. IBM X-Force ID: 144724.
nvd
CVE-2019-4655P4MEDIUMCVSS 4.3≥ 9.1.0, < 9.1.4≥ 9.1.0.0, < 9.1.0.42019-12-30
CVE-2019-4655 [MEDIUM] CVE-2019-4655: IBM MQ 9.1.0.0, 9.1.0.1, 9.1.0.2, 9.1.0.3, 9.1.1, 9.1.2, and 9.1.3 is vulnerable to a denial of serv IBM MQ 9.1.0.0, 9.1.0.1, 9.1.0.2, 9.1.0.3, 9.1.1, 9.1.2, and 9.1.3 is vulnerable to a denial of service attack that would allow an authenticated user to reset client connections due to an error within the Data Conversion routine. IBM X-Force ID: 170966.
nvd
CVE-2023-22874P4MEDIUMCVSS 5.5≥ 9.2.0.0, < 9.3.2≥ 9.3.0.0, < 9.3.0.52023-05-05
CVE-2023-22874 [MEDIUM] CWE-400 CVE-2023-22874: IBM MQ Clients 9.2 CD, 9.3 CD, and 9.3 LTS are vulnerable to a denial of service attack when process IBM MQ Clients 9.2 CD, 9.3 CD, and 9.3 LTS are vulnerable to a denial of service attack when processing configuration files. IBM X-Force ID: 244216.
nvd
CVE-2020-4319P4MEDIUMCVSS 4.3≥ 8.0, < 8.0.0.15≥ 9.1.0.0, < 9.1.0.6+4 more2020-07-28
CVE-2020-4319 [MEDIUM] CWE-209 CVE-2020-4319: IBM MQ, IBM MQ Appliance, and IBM MQ for HPE NonStop 8.0, 9.1 LTS, and 9.1 CD could allow under spec IBM MQ, IBM MQ Appliance, and IBM MQ for HPE NonStop 8.0, 9.1 LTS, and 9.1 CD could allow under special circumstances, an authenticated user to obtain sensitive information due to a data leak from an error message within the pre-v7 pubsub logic. IBM X-Force ID: 177402.
nvd
CVE-2021-38958P4MEDIUMCVSS 5.5v9.2.0.0v9.2.1+5 more2021-11-30
CVE-2021-38958 [MEDIUM] CVE-2021-38958: IBM MQ Appliance 9.2 CD and 9.2 LTS is affected by a denial of service attack caused by a concurrenc IBM MQ Appliance 9.2 CD and 9.2 LTS is affected by a denial of service attack caused by a concurrency issue. IBM X-Force ID: 212042
nvd
CVE-2020-4498P4MEDIUMCVSS 4.4≥ 9.1.0.0, < 9.1.0.6≥ 9.1.0.0, < 9.2.0.0+11 more2020-07-27
CVE-2020-4498 [MEDIUM] CWE-532 CVE-2020-4498: IBM MQ Appliance 9.1 LTS and 9.1 CD could allow a local privileged user to obtain highly sensitve in IBM MQ Appliance 9.1 LTS and 9.1 CD could allow a local privileged user to obtain highly sensitve information due to inclusion of data within trace files. IBM X-Force ID: 182118.
nvd
Ibm Mq Appliance vulnerabilities | cvebase