VendorsIBMintegration_busany version
Vulnerabilities

IBM Integration Bus any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2025-36014
IBM Integration Bus for z/OS code injection
Published 2025-07-07 · Analyzed
8.2EPSS 0.002
CVE-2024-22332
IBM Integration Bus for z/OS denial of service
Published 2024-02-09 · Modified
6.5EPSS 0.006
CVE-2024-27265
IBM Integration Bus for z/OS cross-site request forgery
Published 2024-03-14 · Modified
6.5EPSS 0.002
CVE-2017-1418
IBM Integration Bus 9.0.0.0, 9.0.0.11, 10.0.0.0, and 10.0.0.14 (including IBM WebSphere Message Broker 8.0.0.0 and 8.0.0.9) has insecure permissions on certain files. A local attacker could exploit this vulnerability to modify or delete these files with an unknown impact. IBM X-Force ID: 127406.
Published 2018-11-26 · Modified
5.5EPSS 0.003
CVE-2026-3602
IBM App Connect Enterprise and IBM Integration Bus for z/OS toolkit is vulnerable to an sql injection
Published 2026-06-30 · Modified
5.5EPSS 0.003
CVE-2018-1801
IBM App Connect V11.0.0.0 through V11.0.0.1, IBM Integration Bus V10.0.0.0 through V10.0.0.13, IBM Integration Bus V9.0.0.0 through V9.0.0.10, and WebSphere Message Broker V8.0.0.0 through V8.0.0.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to consume memory resources. IBM X-Force ID: 149639.
Published 2019-02-04 · Modified
5.3EPSS 0.025
CVE-2024-22356
IBM App Connect Enterprise and IBM Integration Bus for z/OS information disclosure
Published 2024-03-26 · Analyzed
4.9EPSS 0.005