Ibm Websphere Mq vulnerabilities
91 known vulnerabilities affecting ibm/websphere_mq.
Total CVEs
91
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH18MEDIUM58LOW12
Vulnerabilities
Page 5 of 5
CVE-2010-0772P4MEDIUMCVSS 4.0v7.0.0v7.0.1+1 more2010-04-27
CVE-2010-0772 [MEDIUM] CVE-2010-0772: Unspecified vulnerability in the channel process in IBM WebSphere MQ 7.0 before 7.0.1.2 allows remot
Unspecified vulnerability in the channel process in IBM WebSphere MQ 7.0 before 7.0.1.2 allows remote authenticated users to cause a denial of service (daemon crash) via "incorrect channel control data."
nvd
CVE-2010-2638P4MEDIUMCVSS 4.0v7.0v7.0.0.1+6 more2010-11-15
CVE-2010-2638 [MEDIUM] CWE-399 CVE-2010-2638: Unspecified vulnerability in IBM WebSphere MQ 7.0 before 7.0.1.5 allows remote authenticated users t
Unspecified vulnerability in IBM WebSphere MQ 7.0 before 7.0.1.5 allows remote authenticated users to cause a denial of service (disk consumption) via vectors that trigger an FDC with an RM680004 Probe Id value.
nvd
CVE-2007-6705P4LOWCVSS 3.3≤ 5.3≤ 6.0.2.02008-03-09
CVE-2007-6705 [LOW] CWE-264 CVE-2007-6705: The WebSphere MQ XA 5.3 before FP13 and 6.0.x before 6.0.2.1 client for Windows, when running in an
The WebSphere MQ XA 5.3 before FP13 and 6.0.x before 6.0.2.1 client for Windows, when running in an MTS or a COM+ environment, grants the PROCESS_DUP_HANDLE privilege to the Everyone group upon connection to a queue manager, which allows local users to duplicate an arbitrary handle and possibly hijack an arbitrary process.
nvd
CVE-2016-0379P4LOWCVSS 3.1v7.5v7.5.0.1+10 more2016-09-26
CVE-2016-0379 [LOW] CWE-19 CVE-2016-0379: IBM WebSphere MQ 7.5 before 7.5.0.7 and 8.0 before 8.0.0.5 mishandles protocol flows, which allows r
IBM WebSphere MQ 7.5 before 7.5.0.7 and 8.0 before 8.0.0.5 mishandles protocol flows, which allows remote authenticated users to cause a denial of service (channel outage) by leveraging queue-manager rights.
nvd
CVE-2017-1699P4LOWCVSS 3.3v8.0v8.0.0.1+10 more2018-01-04
CVE-2017-1699 [LOW] CWE-732 CVE-2017-1699: IBM MQ Managed File Transfer Agent 8.0 and 9.0 sets insecure permissions on certain files it creates
IBM MQ Managed File Transfer Agent 8.0 and 9.0 sets insecure permissions on certain files it creates. A local attacker could exploit this vulnerability to modify or delete data contained in the files with an unknown impact. IBM X-Force ID: 134391.
nvd
CVE-2016-9009P4LOWCVSS 3.1v8.0v8.0.0.0+5 more2017-02-24
CVE-2016-9009 [LOW] CWE-20 CVE-2016-9009: IBM WebSphere MQ 8.0 could allow an authenticated user with authority to create a cluster object to
IBM WebSphere MQ 8.0 could allow an authenticated user with authority to create a cluster object to cause a denial of service to MQ clustering. IBM Reference #: 1998647.
nvd
CVE-2015-7473P4LOWCVSS 2.5v8.0.0.1v8.0.0.2+2 more2016-06-26
CVE-2015-7473 [LOW] CWE-284 CVE-2015-7473: runmqsc in IBM WebSphere MQ 8.x before 8.0.0.5 allows local users to bypass intended queue-manager c
runmqsc in IBM WebSphere MQ 8.x before 8.0.0.5 allows local users to bypass intended queue-manager command access restrictions by leveraging authority for +connect and +dsp.
nvd
CVE-2016-0259P4LOWCVSS 2.5v8.0.0.1v8.0.0.2+2 more2016-06-26
CVE-2016-0259 [LOW] CWE-200 CVE-2016-0259: runmqsc in IBM WebSphere MQ 8.x before 8.0.0.5 allows local users to bypass an intended +dsp authori
runmqsc in IBM WebSphere MQ 8.x before 8.0.0.5 allows local users to bypass an intended +dsp authority requirement and obtain sensitive information via unspecified display commands.
nvd
CVE-2009-0905P4LOWCVSS 1.7v6.0v6.0.1.0+12 more2011-10-30
CVE-2009-0905 [LOW] CWE-20 CVE-2009-0905: IBM WebSphere MQ 6.0 before 6.0.2.8 and 7.0 before 7.0.1.0 does not properly handle long group names
IBM WebSphere MQ 6.0 before 6.0.2.8 and 7.0 before 7.0.1.0 does not properly handle long group names, which might allow local users to gain privileges by leveraging combinations of group names with the same initial substring.
nvd
CVE-2014-4822P4LOWCVSS 1.9v8.0.0.02014-10-19
CVE-2014-4822 [LOW] CWE-255 CVE-2014-4822: IBM WebSphere MQ classes for Java libraries 8.0 before 8.0.0.1 and Websphere MQ Explorer 7.5 before
IBM WebSphere MQ classes for Java libraries 8.0 before 8.0.0.1 and Websphere MQ Explorer 7.5 before 7.5.0.5 and 8.0 before 8.0.0.2 allow local users to discover preconfigured cleartext passwords via an unspecified trace operation.
nvd
CVE-2011-1378P4LOWCVSS 1.9v6.02011-11-26
CVE-2011-1378 [LOW] CWE-264 CVE-2011-1378: IBM WebSphere MQ 6.0 on OpenVMS, when the default rights of the MQM group are established, does not
IBM WebSphere MQ 6.0 on OpenVMS, when the default rights of the MQM group are established, does not properly verify User Authorization File (UAF) data, which allows local users to kill listener processes and the command server via a control command.
nvd
← Previous5 / 5