VendorsIBMmq_applianceall versions
Vulnerabilities

IBM MQ Appliance

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

48CVEs
CVE-2023-22874
IBM MQ denial of service
Published 2023-05-05 · Modified
5.5EPSS 0.002
CVE-2018-1429
IBM MQ Appliance 9.0.1, 9.0.2, 9.0.3, amd 9.0.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 139077.
Published 2018-03-23 · Modified
5.4EPSS 0.010
CVE-2022-22355
IBM MQ Appliance 9.2 CD and 9.2 LTS are vulnerable to a denial of service in the Login component of the application which could allow an attacker to cause a drop in performance.
Published 2022-04-05 · Modified
5.3EPSS 0.011
CVE-2024-51471
IBM MQ Appliance denial of service
Published 2024-12-19 · Analyzed
5.3EPSS 0.003
CVE-2024-54173
IBM MQ information disclosure
Published 2025-02-28 · Analyzed
4.7EPSS 0.001
CVE-2020-4498
IBM MQ Appliance 9.1 LTS and 9.1 CD could allow a local privileged user to obtain highly sensitve information due to inclusion of data within trace files. IBM X-Force ID: 182118.
Published 2020-07-27 · Modified
4.4EPSS 0.003
CVE-2019-4655
IBM MQ 9.1.0.0, 9.1.0.1, 9.1.0.2, 9.1.0.3, 9.1.1, 9.1.2, and 9.1.3 is vulnerable to a denial of service attack that would allow an authenticated user to reset client connections due to an error within the Data Conversion routine. IBM X-Force ID: 170966.
Published 2019-12-30 · Modified
4.3EPSS 0.013
CVE-2020-4319
IBM MQ, IBM MQ Appliance, and IBM MQ for HPE NonStop 8.0, 9.1 LTS, and 9.1 CD could allow under special circumstances, an authenticated user to obtain sensitive information due to a data leak from an error message within the pre-v7 pubsub logic. IBM X-Force ID: 177402.
Published 2020-07-28 · Modified
4.3EPSS 0.007
← Prev2 / 2