Websphere Message Broker
Vendor:
First CVE: Feb 13, 2009 · Active for 17 years
23
Total CVEs
More Total CVEs than 96% of tracked products
2.6
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
4.7
Avg CVSS
Higher Avg CVSS than 7% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Websphere Message Broker over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 13, 2009
17 years ago
Most Recent CVE
Feb 4, 2019
2,731 days ago
CVE Severity & Scoring
Websphere Message Broker23 CVEs
26%
70%
All CVEs353,173 CVEs
45%
40%
11%
LowMediumCritical
Attack Vector
Local4 (17.4%)
Network7 (30.4%)
Unknown12 (52.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (43.5%)
High1 (4.3%)
Unknown12 (52.2%)
User Interaction
None10 (43.5%)
Unknown12 (52.2%)
Required1 (4.3%)
Privileges Required
Low4 (17.4%)
High0 (0.0%)
None7 (30.4%)
Unknown12 (52.2%)
Top CVEs
Signals from CVEs in this product scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-9706CRITICAL IBM Integration Bus 9.0 and 10.0 and WebSphere Message Broker SOAP FLOWS is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processin | Feb 15, 2017 | 9.1 | 23 | NO | NO |
CVE-2017-1418MEDIUM IBM Integration Bus 9.0.0.0, 9.0.0.11, 10.0.0.0, and 10.0.0.14 (including IBM WebSphere Message Broker 8.0.0.0 and 8.0.0.9) has insecure permissions on certain files. A local attac | Nov 26, 2018 | 5.5 | 21 | NO | NO |
CVE-2012-3317MEDIUM IBM WebSphere Message Broker 6.1 before 6.1.0.11, 7.0 before 7.0.0.5, and 8.0 before 8.0.0.2 has incorrect ownership of certain uninstaller Java Runtime Environment (JRE) files, wh | Dec 5, 2012 | 6.9 | 21 | NO | NO |
CVE-2018-1801MEDIUM IBM App Connect V11.0.0.0 through V11.0.0.1, IBM Integration Bus V10.0.0.0 through V10.0.0.13, IBM Integration Bus V9.0.0.0 through V9.0.0.10, and WebSphere Message Broker V8.0.0.0 | Feb 4, 2019 | 5.3 | 20 | NO | NO |
CVE-2016-6080MEDIUM The WebAdmin context for WebSphere Message Broker allows directory listings which could disclose sensitive information to the attacker. | Feb 1, 2017 | 5.3 | 20 | NO | NO |
CVE-2014-6170MEDIUM The HTTPInput node in IBM WebSphere Message Broker 7.0 before 7.0.0.8 and 8.0 before 8.0.0.6 and IBM Integration Bus 9.0 before 9.0.0.4 allows remote attackers to obtain sensitive | Feb 2, 2015 | 5.0 | 18 | NO | NO |
CVE-2012-5952MEDIUM IBM WebSphere Message Broker 6.1 before 6.1.0.12, 7.0 before 7.0.0.6, and 8.0 before 8.0.0.2 does not validate Basic Authentication credentials before proceeding to WS-Addressing a | Feb 20, 2013 | 5.0 | 18 | NO | NO |
CVE-2016-9010MEDIUM IBM WebSphere Message Broker 9.0 and 10.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote | Feb 15, 2017 | 6.1 | 17 | NO | NO |
CVE-2016-2961MEDIUM The integration server in IBM Integration Bus 9 before 9.0.0.6 and 10 before 10.0.0.5 and WebSphere Message Broker 8 before 8.0.0.8 allows remote attackers to obtain sensitive Tomc | Jul 2, 2016 | 5.3 | 17 | NO | NO |
IBM Integration Bus 9 and 10 before 10.0.0.1 and WebSphere Message Broker 7 before 7.0.0.8 and 8 before 8.0.0.7 do not ensure that the correct security profile is selected, which a | Aug 23, 2015 | 3.5 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (23 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (23 CVEs).
Media Mentions
Signals from CVEs in this product scope (23 CVEs).
Top CNAs Publishing CVEs For Websphere Message Broker
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.0.0.8 | 2 | 3.9 | 0.8% | 0 | 0 |
| 8.0.0.7 | 4 | 4.7 | 0.8% | 0 | 0 |
| 8.0.0.6 | 5 | 4.4 | 0.8% | 0 | 0 |
| 8.0.0.5 | 11 | 4.3 | 0.9% | 0 | 0 |
| 8.0.0.4 | 11 | 4.3 | 0.9% | 0 | 0 |
| 8.0.0.3 | 12 | 4.3 | 1.1% | 0 | 0 |
| 8.0.0.2 | 13 | 4.3 | 1.2% | 0 | 0 |
| 8.0.0.1 | 17 | 4.4 | 1.1% | 0 | 0 |
| 8.0.0.0 | 2 | 5.4 | 0.8% | 0 | 0 |
| 8.0 | 18 | 4.7 | 1.2% | 0 | 0 |
| 7.0.0.7 | 3 | 4.6 | 1.4% | 0 | 0 |
| 7.0.0.6 | 4 | 4.5 | 1.7% | 0 | 0 |
| 7.0.0.5 | 9 | 4.3 | 1.5% | 0 | 0 |
| 7.0.0.4 | 10 | 4.5 | 1.4% | 0 | 0 |
| 7.0.0.3 | 10 | 4.5 | 1.4% | 0 | 0 |
| 7.0.0.2 | 10 | 4.5 | 1.4% | 0 | 0 |
| 7.0.0.1 | 10 | 4.5 | 1.4% | 0 | 0 |
| 7.0. | 10 | 4.5 | 1.4% | 0 | 0 |
| 6.1.0.9 | 4 | 5.1 | 1.5% | 0 | 0 |
| 6.1.0.8 | 4 | 5.1 | 1.5% | 0 | 0 |