Websphere Message Broker

Vendor:

First CVE: Feb 13, 2009 · Active for 17 years

23
Total CVEs
More Total CVEs than 96% of tracked products
2.6
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
4.7
Avg CVSS
Higher Avg CVSS than 7% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Websphere Message Broker over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 13, 2009
17 years ago
Most Recent CVE
Feb 4, 2019
2,731 days ago

CVE Severity & Scoring

Websphere Message Broker23 CVEs
All CVEs353,173 CVEs
LowMediumCritical
Attack Vector
Local4 (17.4%)
Network7 (30.4%)
Unknown12 (52.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (43.5%)
High1 (4.3%)
Unknown12 (52.2%)
User Interaction
None10 (43.5%)
Unknown12 (52.2%)
Required1 (4.3%)
Privileges Required
Low4 (17.4%)
High0 (0.0%)
None7 (30.4%)
Unknown12 (52.2%)

Top CVEs

Signals from CVEs in this product scope (23 CVEs).

23 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
IBM Integration Bus 9.0 and 10.0 and WebSphere Message Broker SOAP FLOWS is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processin
Feb 15, 20179.123NONO
IBM Integration Bus 9.0.0.0, 9.0.0.11, 10.0.0.0, and 10.0.0.14 (including IBM WebSphere Message Broker 8.0.0.0 and 8.0.0.9) has insecure permissions on certain files. A local attac
Nov 26, 20185.521NONO
IBM WebSphere Message Broker 6.1 before 6.1.0.11, 7.0 before 7.0.0.5, and 8.0 before 8.0.0.2 has incorrect ownership of certain uninstaller Java Runtime Environment (JRE) files, wh
Dec 5, 20126.921NONO
IBM App Connect V11.0.0.0 through V11.0.0.1, IBM Integration Bus V10.0.0.0 through V10.0.0.13, IBM Integration Bus V9.0.0.0 through V9.0.0.10, and WebSphere Message Broker V8.0.0.0
Feb 4, 20195.320NONO
The WebAdmin context for WebSphere Message Broker allows directory listings which could disclose sensitive information to the attacker.
Feb 1, 20175.320NONO
The HTTPInput node in IBM WebSphere Message Broker 7.0 before 7.0.0.8 and 8.0 before 8.0.0.6 and IBM Integration Bus 9.0 before 9.0.0.4 allows remote attackers to obtain sensitive
Feb 2, 20155.018NONO
IBM WebSphere Message Broker 6.1 before 6.1.0.12, 7.0 before 7.0.0.6, and 8.0 before 8.0.0.2 does not validate Basic Authentication credentials before proceeding to WS-Addressing a
Feb 20, 20135.018NONO
IBM WebSphere Message Broker 9.0 and 10.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote
Feb 15, 20176.117NONO
The integration server in IBM Integration Bus 9 before 9.0.0.6 and 10 before 10.0.0.5 and WebSphere Message Broker 8 before 8.0.0.8 allows remote attackers to obtain sensitive Tomc
Jul 2, 20165.317NONO
IBM Integration Bus 9 and 10 before 10.0.0.1 and WebSphere Message Broker 7 before 7.0.0.8 and 8 before 8.0.0.7 do not ensure that the correct security profile is selected, which a
Aug 23, 20153.517NONO

Exploit Exposure

Signals from CVEs in this product scope (23 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (23 CVEs).

Media Mentions

Signals from CVEs in this product scope (23 CVEs).

Top CNAs Publishing CVEs For Websphere Message Broker

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8.0.0.823.90.8%00
8.0.0.744.70.8%00
8.0.0.654.40.8%00
8.0.0.5114.30.9%00
8.0.0.4114.30.9%00
8.0.0.3124.31.1%00
8.0.0.2134.31.2%00
8.0.0.1174.41.1%00
8.0.0.025.40.8%00
8.0184.71.2%00
7.0.0.734.61.4%00
7.0.0.644.51.7%00
7.0.0.594.31.5%00
7.0.0.4104.51.4%00
7.0.0.3104.51.4%00
7.0.0.2104.51.4%00
7.0.0.1104.51.4%00
7.0.104.51.4%00
6.1.0.945.11.5%00
6.1.0.845.11.5%00