VYPR

Mq Appliance

by IBM

CVEs (58)

  • CVE-2020-4682CriJan 28, 2021
    risk 0.64cvss 9.8epss 0.08

    IBM MQ 7.5, 8.0, 9.0, 9.1, 9.2 LTS, and 9.2 CD could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization of trusted data. An attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 186509.

  • CVE-2025-0975HigFeb 28, 2025
    risk 0.57cvss 8.8epss 0.01

    IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD console could allow an authenticated user to execute code due to improper neutralization of escape characters.

  • CVE-2020-4938HigJul 12, 2021
    risk 0.57cvss 8.8epss 0.00

    IBM MQ Appliance 9.1 and 9.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 191815.

  • CVE-2017-1318HigJul 18, 2017
    risk 0.57cvss 8.8epss 0.03

    IBM MQ Appliance 8.0 and 9.0 could allow an authenticated messaging administrator to execute arbitrary commands on the system, caused by command execution. IBM X-Force ID: 125730.

  • CVE-2016-5879HigSep 2, 2016
    risk 0.57cvss 8.8epss 0.00

    MQCLI on IBM MQ Appliance M2000 and M2001 devices allows local users to execute arbitrary shell commands via a crafted (1) Disaster Recovery or (2) High Availability command.

  • CVE-2019-4620HigJan 28, 2020
    risk 0.51cvss 7.8epss 0.00

    IBM MQ Appliance 8.0 and 9.0 LTS could allow a local attacker to bypass security restrictions caused by improper validation of environment variables. IBM X-Force ID: 168863.

  • CVE-2019-4294HigAug 20, 2019
    risk 0.51cvss 7.8epss 0.01

    IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.6, 7.6.0.0 through 7.6.0.15 and IBM MQ Appliance 8.0.0.0 through 8.0.0.12, 9.1.0.0 through 9.1.0.2, and 9.1.1 through 9.1.2 could allow a local attacker to execute arbitrary commands on the system, caused by a command injection…

  • CVE-2024-25048HigApr 27, 2024
    risk 0.49cvss 7.5epss 0.01

    IBM MQ Appliance 9.3 CD and LTS are vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote authenticated attacker could overflow a buffer and execute arbitrary code on the system or cause the server to crash. IBM X-Force ID: 283137.

  • CVE-2024-25016HigMar 3, 2024
    risk 0.49cvss 7.5epss 0.01

    IBM MQ and IBM MQ Appliance 9.0, 9.1, 9.2, 9.3 LTS and 9.3 CD could allow a remote unauthenticated attacker to cause a denial of service due to incorrect buffering logic. IBM X-Force ID: 281279.

  • CVE-2020-4870HigDec 21, 2020
    risk 0.49cvss 7.5epss 0.02

    IBM MQ 9.2 CD and LTS are vulnerable to a denial of service attack caused by an error processing connecting applications. IBM X-Force ID: 190833.

  • CVE-2020-4375HigJul 28, 2020
    risk 0.49cvss 7.5epss 0.02

    IBM MQ, IBM MQ Appliance, IBM MQ for HPE NonStop 8.0, 9.1 CD, and 9.1 LTS could allow an attacker to cause a denial of service due to a memory leak caused by an error creating a dynamic queue. IBM X-Force ID: 179080.

  • CVE-2020-4310HigJun 16, 2020
    risk 0.49cvss 7.5epss 0.02

    IBM MQ and MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 C are vulnerable to a denial of service attack due to an error within the Data Conversion logic. IBM X-Force ID: 177081.

  • CVE-2019-4055HigApr 19, 2019
    risk 0.49cvss 7.5epss 0.02

    IBM MQ 8.0.0.0 through 8.0.0.10, 9.0.0.0 through 9.0.0.5, and 9.1.0.0 through 9.1.1 is vulnerable to a denial of service attack within the TLS key renegotiation function. IBM X-Force ID: 156564.

  • CVE-2023-46176MedNov 3, 2023
    risk 0.44cvss 6.7epss 0.00

    IBM MQ Appliance 9.3 CD could allow a local attacker to gain elevated privileges on the system, caused by improper validation of security keys. IBM X-Force ID: 269535.

  • CVE-2021-38967MedNov 30, 2021
    risk 0.44cvss 6.7epss 0.00

    IBM MQ Appliance 9.2 CD and 9.2 LTS could allow a local privileged user to inject and execute malicious code. IBM X-Force ID: 212441.

  • CVE-2025-3631MedJul 11, 2025
    risk 0.42cvss 6.5epss 0.00

    An IBM MQ 9.3 and 9.4 Client connecting to an MQ Queue Manager can cause a SIGSEGV in the AMQRMPPA channel process terminating it.

  • CVE-2025-23225MedFeb 28, 2025
    risk 0.42cvss 6.5epss 0.00

    IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow an authenticated user to cause a denial of service due to the improper handling of invalid headers sent to the queue.

  • CVE-2024-51470MedDec 18, 2024
    risk 0.42cvss 6.5epss 0.01

    IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, 9.4 CD, IBM MQ Appliance 9.3 LTS, 9.3 CD, 9.4 LTS, and IBM MQ for HPE NonStop 8.1.0 through 8.1.0.25 could allow an authenticated user to cause a denial-of-service due to messages with improperly set values.

  • CVE-2023-46177MedDec 18, 2023
    risk 0.42cvss 6.5epss 0.01

    IBM MQ Appliance 9.3 LTS and 9.3 CD could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request to view arbitrary files on the system. IBM X-Force ID: 269536.

  • CVE-2022-43902MedMar 10, 2023
    risk 0.42cvss 6.5epss 0.01

    IBM MQ 9.2 CD, 9.2 LTS, 9.3 CD, and 9.3 LTS is vulnerable to a denial of service attack caused by specially crafted PCF or MQSC messages. IBM X-Force ID: 240832.

Page 1 of 3