Integration Bus

Vendor:

First CVE: Sep 18, 2014 · Active for 11 years

24
Total CVEs
More Total CVEs than 95% of tracked products
2.4
Avg CVEs / Year
Higher CVE frequency than 74% of tracked products
5.3
Avg CVSS
Higher Avg CVSS than 11% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Integration Bus over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 18, 2014
11 years ago
Most Recent CVE
Jun 30, 2026
24 days ago

CVE Severity & Scoring

Integration Bus24 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local7 (29.2%)
Network12 (50.0%)
Unknown5 (20.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (62.5%)
High4 (16.7%)
Unknown5 (20.8%)
User Interaction
None16 (66.7%)
Unknown5 (20.8%)
Required3 (12.5%)
Privileges Required
Low6 (25.0%)
High2 (8.3%)
None11 (45.8%)
Unknown5 (20.8%)

Top CVEs

Signals from CVEs in this product scope (24 CVEs).

24 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.26 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 is vulnerable to SQL injection. A r
Jun 30, 20265.530NONO
IBM Integration Bus 9.0 and 10.0 transmits user credentials in plain in clear text which can be read by an attacker using man in the middle techniques. IBM X-Force ID: 134165.
Dec 20, 20178.125NONO
IBM Integration Bus 9.0 and 10.0 and WebSphere Message Broker SOAP FLOWS is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processin
Feb 15, 20179.123NONO
IBM Integration Bus 9.0.0.0, 9.0.0.11, 10.0.0.0, and 10.0.0.14 (including IBM WebSphere Message Broker 8.0.0.0 and 8.0.0.9) has insecure permissions on certain files. A local attac
Nov 26, 20185.521NONO
IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.5 is vulnerable to code injection by a privileged user with access to the IIB install directory.
Jul 7, 20256.720NONO
IBM Integration Bus for z/OS 10.1 through 10.1.0.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitt
Mar 14, 20246.520NONO
The IBM Integration Bus for z/OS 10.1 through 10.1.0.2 AdminAPI is vulnerable to a denial of service due to file system exhaustion. IBM X-Force ID: 279972.
Feb 9, 20246.520NONO
IBM App Connect V11.0.0.0 through V11.0.0.1, IBM Integration Bus V10.0.0.0 through V10.0.0.13, IBM Integration Bus V9.0.0.0 through V9.0.0.10, and WebSphere Message Broker V8.0.0.0
Feb 4, 20195.320NONO
IBM Integration Bus 9.0 and 10.0 could allow an attacker that has captured a valid session id to hijack another users session during a small timeframe before the session times out.
Jan 19, 20185.619NONO
IBM App Connect Enterprise 11.0.0.1 through 11.0.0.23, 12.0.1.0 through 12.0.9.0 and IBM Integration Bus for z/OS 10.1 through 10.1.0.2store potentially sensitive information in lo
Mar 26, 20244.918NONO

Exploit Exposure

Signals from CVEs in this product scope (24 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (24 CVEs).

Media Mentions

Signals from CVEs in this product scope (24 CVEs).

Top CNAs Publishing CVEs For Integration Bus

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.0.0.918.10.8%00
9.0.0.836.31.0%00
9.0.0.755.40.7%00
9.0.0.655.40.7%00
9.0.0.565.40.8%00
9.0.0.465.40.8%00
9.0.0.384.90.8%00
9.0.0.2124.80.9%00
9.0.0.1124.80.9%00
9.0.0.036.31.0%00
9.0.015.50.3%00
9.0114.71.0%00
10.115.50.2%00
10.0.0.936.31.0%00
10.0.0.836.31.0%00
10.0.0.755.40.7%00
10.0.0.655.40.7%00
10.0.0.555.40.7%00
10.0.0.465.40.8%00
10.0.0.365.40.8%00