VendorsIBMmqall versions
Vulnerabilities

IBM Mq

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

53CVEs
CVE-2020-4682
IBM MQ 7.5, 8.0, 9.0, 9.1, 9.2 LTS, and 9.2 CD could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization of trusted data. An attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 186509.
Published 2021-01-28 · Modified
10.0EPSS 0.078
CVE-2026-10027
IBM MQ queue manager is vulnerable to unauthenticated remote code execution
Published 2026-09-18 · Analyzed
9.8EPSS 0.004
CVE-2022-22489
IBM MQ 8.0, (9.0, 9.1, 9.2 LTS), and (9.1 and 9.2 CD) are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 226339.
Published 2022-08-19 · Modified
9.1EPSS 0.017
CVE-2024-31912
IBM MQ privilege escalation
Published 2024-06-28 · Modified
8.8EPSS 0.004
CVE-2026-10853
IBM MQ queue manager is vulnerable to remote code execution
Published 2026-09-18 · Analyzed
8.8EPSS 0.004
CVE-2026-11375
IBM MQ queue manager is vulnerable to remote code execution
Published 2026-09-18 · Analyzed
8.8EPSS 0.003
CVE-2026-11378
IBM MQ queue manager is vulnerable to remote code execution
Published 2026-09-18 · Analyzed
8.8EPSS 0.003
CVE-2026-10575
IBM MQ queue manager is vulnerable to remote code execution
Published 2026-09-18 · Analyzed
8.8EPSS 0.003
CVE-2018-1883
A problem within the IBM MQ 9.0.2, 9.0.3, 9.0.4, 9.0.5, and 9.1.0.0 Console REST API Could allow attackers to execute a denial of service attack preventing users from logging into the MQ Console REST API. IBM X-Force ID: 151969.
Published 2018-12-07 · Modified
7.5EPSS 0.024
CVE-2019-4055
IBM MQ 8.0.0.0 through 8.0.0.10, 9.0.0.0 through 9.0.0.5, and 9.1.0.0 through 9.1.1 is vulnerable to a denial of service attack within the TLS key renegotiation function. IBM X-Force ID: 156564.
Published 2019-04-19 · Modified
7.5EPSS 0.021
CVE-2020-4870
IBM MQ 9.2 CD and LTS are vulnerable to a denial of service attack caused by an error processing connecting applications. IBM X-Force ID: 190833.
Published 2020-12-21 · Modified
7.5EPSS 0.017
CVE-2019-4762
IBM MQ 9.0 and 9.1 is vulnerable to a denial of service attack due to an error in the Channel processing function. IBM X-Force ID: 173625.
Published 2020-04-16 · Modified
7.5EPSS 0.016
CVE-2020-4310
IBM MQ and MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 C are vulnerable to a denial of service attack due to an error within the Data Conversion logic. IBM X-Force ID: 177081.
Published 2020-06-16 · Modified
7.5EPSS 0.016
CVE-2021-39034
IBM MQ 9.1 LTS is vulnerable to a denial of service attack caused by an issue within the channel process. IBM X-Force ID: 213964.
Published 2022-02-17 · Modified
7.5EPSS 0.012
CVE-2019-4227
IBM MQ 8.0.0.4 - 8.0.0.12, 9.0.0.0 - 9.0.0.6, 9.1.0.0 - 9.1.0.2, and 9.1.0 - 9.1.2 AMQP Listeners could allow an unauthorized user to conduct a session fixation attack due to clients not being disconnected as they should. IBM X-Force ID: 159352.
Published 2019-10-04 · Modified
7.5EPSS 0.011
CVE-2023-28513
IBM MQ denial of service
Published 2023-07-19 · Modified
7.5EPSS 0.010
CVE-2024-25015
IBM MQ denial of service
Published 2024-05-01 · Analyzed
7.5EPSS 0.009
CVE-2024-25016
IBM MQ denial of service
Published 2024-03-03 · Analyzed
7.5EPSS 0.008
CVE-2024-35116
IBM MQ denial of service
Published 2024-06-28 · Modified
7.5EPSS 0.007
CVE-2025-36128
IBM MQ denial of service
Published 2025-10-16 · Analyzed
7.5EPSS 0.005
CVE-2024-31919
IBM MQ denial of service
Published 2024-06-28 · Modified
7.5EPSS 0.005
CVE-2019-4261
IBM WebSphere MQ V7.1, 7.5, IBM MQ V8, IBM MQ V9.0LTS, IBM MQ V9.1 LTS, and IBM MQ V9.1 CD are vulnerable to a denial of service attack caused by specially crafted messages. IBM X-Force ID: 160013.
Published 2019-08-05 · Modified
6.5EPSS 0.024
CVE-2019-4378
IBM MQ 7.5.0.0 - 7.5.0.9, 7.1.0.0 - 7.1.0.9, 8.0.0.0 - 8.0.0.12, 9.0.0.0 - 9.0.0.6, 9.1.0.0 - 9.1.0.2, and 9.1.0 - 9.1.2 command server is vulnerable to a denial of service attack caused by an authenticated and authorized user using specially crafted PCF messages. IBM X-Force ID: 162084.
Published 2019-09-26 · Modified
6.5EPSS 0.016
CVE-2019-4614
IBM MQ and IBM MQ Appliance 8.0 and 9.0 LTS client connecting to a Queue Manager could cause a SIGSEGV denial of service caused by converting an invalid message. IBM X-Force ID: 168639.
Published 2020-01-28 · Modified
6.5EPSS 0.016
CVE-2019-4656
IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD is vulnerable to a denial of service attack that would allow an authenticated user to crash the queue and require a restart due to an error processing error messages. IBM X-Force ID: 170967.
Published 2020-03-16 · Modified
6.5EPSS 0.014
CVE-2020-4267
IBM MQ and MQ Appliance 8.0, 9.1 LTS, and 9.1 CD could allow an authenticated user cause a denial of service due to a memory leak. IBM X-Force ID: 175840.
Published 2020-04-24 · Modified
6.5EPSS 0.013
CVE-2020-4931
IBM MQ 9.1 LTS, 9.2 LTS, and 9.1 CD AMQP Channels could allow an authenticated user to cause a denial of service due to an issue processing messages. IBM X-Force ID: 191747.
Published 2021-02-24 · Modified
6.5EPSS 0.012
CVE-2021-38875
IBM MQ 8.0, 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.1 CD, and 9.2 CD is vulnerable to a denial of service attack caused by an error processing messages. IBM X-Force ID: 208398.
Published 2021-11-23 · Modified
6.5EPSS 0.010
CVE-2022-31772
IBM MQ denial of service
Published 2022-11-11 · Modified
6.5EPSS 0.008
CVE-2020-4320
IBM MQ Appliance and IBM MQ AMQP Channels 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD do not correctly block or allow clients based on the certificate distinguished name SSLPEER setting. IBM X-Force ID: 177403.
Published 2020-06-16 · Modified
6.5EPSS 0.007
CVE-2024-35155
IBM MQ information disclosure
Published 2024-06-28 · Modified
6.5EPSS 0.006
CVE-2024-35156
IBM MQ information disclosure
Published 2024-06-28 · Modified
6.5EPSS 0.005
CVE-2025-0985
IBM MQ information disclosure
Published 2025-02-28 · Analyzed
6.5EPSS 0.003
CVE-2019-4049
IBM MQ 9.1.0.0, 9.1.0.1, 9.1.1, and 9.1.0.2 is vulnerable to a denial of service due to a local user being able to fill up the disk space of the underlying filesystem using the error logging service. IBM X-Force ID: 156398.
Published 2019-08-20 · Modified
6.2EPSS 0.003
CVE-2024-52896
IBM MQ information disclosure
Published 2024-12-19 · Analyzed
6.2EPSS 0.003
CVE-2024-52897
IBM MQ information disclosure
Published 2024-12-19 · Analyzed
6.2EPSS 0.002
CVE-2023-28514
IBM MQ information disclosure
Published 2023-05-19 · Modified
6.2EPSS 0.002
CVE-2024-52898
IBM MQ information disclosure
Published 2025-01-14 · Analyzed
6.2EPSS 0.002
CVE-2021-38949
IBM MQ 7.5, 8.0, 9.0 LTS, 9.1 CD, and 9.1 LTS stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 211403.
Published 2021-11-16 · Modified
6.2EPSS 0.002
CVE-2019-4568
IBM MQ and IBM MQ Appliance 8.0 and 9.0 LTS could allow a remote attacker with intimate knowledge of the server to cause a denial of service when receiving data on the channel. IBM X-Force ID: 166629.
Published 2020-01-28 · Modified
5.9EPSS 0.013
1 / 2Next →