Integration Bus
Vendor:
First CVE: Sep 18, 2014 · Active for 11 years
24
Total CVEs
More Total CVEs than 95% of tracked products
2.4
Avg CVEs / Year
Higher CVE frequency than 74% of tracked products
5.3
Avg CVSS
Higher Avg CVSS than 11% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Integration Bus over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 18, 2014
11 years ago
Most Recent CVE
Jun 30, 2026
24 days ago
CVE Severity & Scoring
Integration Bus24 CVEs
17%
75%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local7 (29.2%)
Network12 (50.0%)
Unknown5 (20.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (62.5%)
High4 (16.7%)
Unknown5 (20.8%)
User Interaction
None16 (66.7%)
Unknown5 (20.8%)
Required3 (12.5%)
Privileges Required
Low6 (25.0%)
High2 (8.3%)
None11 (45.8%)
Unknown5 (20.8%)
Top CVEs
Signals from CVEs in this product scope (24 CVEs).
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-3602MEDIUM IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.26 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 is vulnerable to SQL injection. A r | Jun 30, 2026 | 5.5 | 30 | NO | NO |
CVE-2017-1694HIGH IBM Integration Bus 9.0 and 10.0 transmits user credentials in plain in clear text which can be read by an attacker using man in the middle techniques. IBM X-Force ID: 134165. | Dec 20, 2017 | 8.1 | 25 | NO | NO |
CVE-2016-9706CRITICAL IBM Integration Bus 9.0 and 10.0 and WebSphere Message Broker SOAP FLOWS is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processin | Feb 15, 2017 | 9.1 | 23 | NO | NO |
CVE-2017-1418MEDIUM IBM Integration Bus 9.0.0.0, 9.0.0.11, 10.0.0.0, and 10.0.0.14 (including IBM WebSphere Message Broker 8.0.0.0 and 8.0.0.9) has insecure permissions on certain files. A local attac | Nov 26, 2018 | 5.5 | 21 | NO | NO |
CVE-2025-36014MEDIUM IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.5 is vulnerable to code injection by a privileged user with access to the IIB install directory. | Jul 7, 2025 | 6.7 | 20 | NO | NO |
CVE-2024-27265MEDIUM IBM Integration Bus for z/OS 10.1 through 10.1.0.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitt | Mar 14, 2024 | 6.5 | 20 | NO | NO |
CVE-2024-22332MEDIUM The IBM Integration Bus for z/OS 10.1 through 10.1.0.2 AdminAPI is vulnerable to a denial of service due to file system exhaustion. IBM X-Force ID: 279972. | Feb 9, 2024 | 6.5 | 20 | NO | NO |
CVE-2018-1801MEDIUM IBM App Connect V11.0.0.0 through V11.0.0.1, IBM Integration Bus V10.0.0.0 through V10.0.0.13, IBM Integration Bus V9.0.0.0 through V9.0.0.10, and WebSphere Message Broker V8.0.0.0 | Feb 4, 2019 | 5.3 | 20 | NO | NO |
CVE-2017-1693MEDIUM IBM Integration Bus 9.0 and 10.0 could allow an attacker that has captured a valid session id to hijack another users session during a small timeframe before the session times out. | Jan 19, 2018 | 5.6 | 19 | NO | NO |
CVE-2024-22356MEDIUM IBM App Connect Enterprise 11.0.0.1 through 11.0.0.23, 12.0.1.0 through 12.0.9.0 and IBM Integration Bus for z/OS 10.1 through 10.1.0.2store potentially sensitive information in lo | Mar 26, 2024 | 4.9 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (24 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (24 CVEs).
Media Mentions
Signals from CVEs in this product scope (24 CVEs).
Top CNAs Publishing CVEs For Integration Bus
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.0.0.9 | 1 | 8.1 | 0.8% | 0 | 0 |
| 9.0.0.8 | 3 | 6.3 | 1.0% | 0 | 0 |
| 9.0.0.7 | 5 | 5.4 | 0.7% | 0 | 0 |
| 9.0.0.6 | 5 | 5.4 | 0.7% | 0 | 0 |
| 9.0.0.5 | 6 | 5.4 | 0.8% | 0 | 0 |
| 9.0.0.4 | 6 | 5.4 | 0.8% | 0 | 0 |
| 9.0.0.3 | 8 | 4.9 | 0.8% | 0 | 0 |
| 9.0.0.2 | 12 | 4.8 | 0.9% | 0 | 0 |
| 9.0.0.1 | 12 | 4.8 | 0.9% | 0 | 0 |
| 9.0.0.0 | 3 | 6.3 | 1.0% | 0 | 0 |
| 9.0.0 | 1 | 5.5 | 0.3% | 0 | 0 |
| 9.0 | 11 | 4.7 | 1.0% | 0 | 0 |
| 10.1 | 1 | 5.5 | 0.2% | 0 | 0 |
| 10.0.0.9 | 3 | 6.3 | 1.0% | 0 | 0 |
| 10.0.0.8 | 3 | 6.3 | 1.0% | 0 | 0 |
| 10.0.0.7 | 5 | 5.4 | 0.7% | 0 | 0 |
| 10.0.0.6 | 5 | 5.4 | 0.7% | 0 | 0 |
| 10.0.0.5 | 5 | 5.4 | 0.7% | 0 | 0 |
| 10.0.0.4 | 6 | 5.4 | 0.8% | 0 | 0 |
| 10.0.0.3 | 6 | 5.4 | 0.8% | 0 | 0 |