Mq

Vendor:

First CVE: Dec 7, 2018 · Active for 7 years

48
Total CVEs
More Total CVEs than 97% of tracked products
5.3
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 29% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Mq over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 7, 2018
7 years ago
Most Recent CVE
Mar 3, 2026
145 days ago

CVE Severity & Scoring

Mq48 CVEs
All CVEs352,719 CVEs
LowMediumHighCritical
Attack Vector
Local15 (31.3%)
Network33 (68.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low46 (95.8%)
High2 (4.2%)
Unknown0 (0.0%)
User Interaction
None46 (95.8%)
Unknown0 (0.0%)
Required2 (4.2%)
Privileges Required
Low29 (60.4%)
High0 (0.0%)
None19 (39.6%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (48 CVEs).

48 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
IBM MQ 7.5, 8.0, 9.0, 9.1, 9.2 LTS, and 9.2 CD could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization of trusted data. An attack
Jan 28, 20219.830NONO
IBM MQ 8.0, (9.0, 9.1, 9.2 LTS), and (9.1 and 9.2 CD) are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this
Aug 19, 20229.129NONO
IBM MQ and MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 C are vulnerable to a denial of service attack due to an error within the Data Conversion logic. IBM X-Force ID: 17
Jun 16, 20207.526NONO
IBM MQ 8.0.0.0 through 8.0.0.10, 9.0.0.0 through 9.0.0.5, and 9.1.0.0 through 9.1.1 is vulnerable to a denial of service attack within the TLS key renegotiation function. IBM X-For
Apr 19, 20197.526NONO
IBM MQ 9.1, 9.2, 9.3, 9.4 LTS and 9.3, 9.4 CD is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations. By conducting slowl
Oct 16, 20257.525NONO
IBM MQ 9.1 LTS is vulnerable to a denial of service attack caused by an issue within the channel process. IBM X-Force ID: 213964.
Feb 17, 20227.525NONO
A problem within the IBM MQ 9.0.2, 9.0.3, 9.0.4, 9.0.5, and 9.1.0.0 Console REST API Could allow attackers to execute a denial of service attack preventing users from logging into
Dec 7, 20187.525NONO
IBM MQ 9.3 LTS and 9.3 CD could allow an authenticated user to escalate their privileges under certain configurations due to incorrect privilege assignment. IBM X-Force ID: 28989
Jun 28, 20248.824NONO
IBM MQ 9.0 and 9.1 is vulnerable to a denial of service attack due to an error in the Channel processing function. IBM X-Force ID: 173625.
Apr 16, 20207.524NONO
IBM MQ 8.0, 9.0 LTS, 9.1 CD, 9.1 LTS, 9.2 CD, and 9.2 LTS could allow an authenticated and authorized user to cause a denial of service to the MQTT channels. IBM X-Force ID: 22833
Nov 11, 20226.523NONO

Exploit Exposure

Signals from CVEs in this product scope (48 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (48 CVEs).

Media Mentions

Signals from CVEs in this product scope (48 CVEs).

Top CNAs Publishing CVEs For Mq

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.4.0.017.50.5%00
9.4.036.30.3%00
9.3.0.017.50.5%00
9.3.096.50.4%00
9.2.1.019.87.8%00
9.2.0.037.93.1%00
9.2.086.60.9%00
9.1.0.619.87.8%00
9.1.0.519.87.8%00
9.1.0.419.87.8%00
9.1.0.319.87.8%00
9.1.0.219.87.8%00
9.1.0.119.87.8%00
9.1.0.0126.91.4%00
9.1.066.20.8%00
9.0.0.919.87.8%00
9.0.0.819.87.8%00
9.0.0.719.87.8%00
9.0.0.619.87.8%00
9.0.0.519.87.8%00