Websphere Mq

Vendor:

First CVE: Nov 20, 2007 · Active for 18 years

89
Total CVEs
More Total CVEs than 99% of tracked products
5.6
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
5.7
Avg CVSS
Higher Avg CVSS than 20% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Websphere Mq over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 20, 2007
18 years ago
Most Recent CVE
Sep 29, 2022
1,398 days ago

CVE Severity & Scoring

Websphere Mq89 CVEs
All CVEs353,240 CVEs
LowMediumHighCritical
Attack Vector
Local16 (18.0%)
Network38 (42.7%)
Unknown35 (39.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low38 (42.7%)
High16 (18.0%)
Unknown35 (39.3%)
User Interaction
None54 (60.7%)
Unknown35 (39.3%)
Required0 (0.0%)
Privileges Required
Low41 (46.1%)
High1 (1.1%)
None12 (13.5%)
Unknown35 (39.3%)

Top CVEs

Signals from CVEs in this product scope (89 CVEs).

89 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Multiple cross-site request forgery (CSRF) vulnerabilities in the Web Gateway component in IBM WebSphere MQ File Transfer Edition 7.0.4 and earlier, and WebSphere MQ - Managed File
Aug 17, 20126.832NOYES
IBM MQ 7.5, 8.0, 9.0, 9.1, 9.2 LTS, and 9.2 CD could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization of trusted data. An attack
Jan 28, 20219.830NONO
Buffer overflow in the queue manager in IBM WebSphere MQ 6.x before 6.0.2.7 and 7.x before 7.0.1.0 allows remote attackers to execute arbitrary code via a crafted request.
Jun 3, 200910.029NONO
Multiple unspecified vulnerabilities in IBM WebSphere MQ 6.0 have unknown impact and remote attack vectors involving "memory corruption." NOTE: as of 20071116, the only disclosure
Nov 20, 200710.027NONO
IBM WebSphere MQ 7.1 is vulnerable to a denial of service, caused by an error when handling user ids. A remote attacker could exploit this vulnerability to bypass the security conf
Sep 29, 20227.526NONO
IBM MQ and MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 C are vulnerable to a denial of service attack due to an error within the Data Conversion logic. IBM X-Force ID: 17
Jun 16, 20207.526NONO
IBM WebSphere MQ 8.0.0.0 through 8.0.0.10, 9.0.0.0 through 9.0.0.5, 9.0.1 through 9.0.5, and 9.1.0.0 could allow a local user to inject code that could be executed with root privil
Nov 13, 20187.826NONO
IBM WebSphere MQ 9.0.1 and 9.0.2 Java/JMS application can incorrectly transmit user credentials in plain text. IBM X-Force ID: 126245.
Jul 10, 20178.126NONO
IBM WebSphere MQ 8.0.0.0 through 9.1.1 could allow a local user to inject code that could be executed with root privileges. This is due to an incomplete fix for CVE-2018-1792. IBM
Mar 11, 20197.825NONO
IBM WebSphere 8.0.0.0 through 9.1.1 could allow an authenticated attacker to escalate their privileges when using multiplexed channels. IBM X-Force ID: 153915.
Mar 11, 20197.525NONO

Exploit Exposure

Signals from CVEs in this product scope (89 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
2.2% of CVEs· 85th percentile

Social Chatter

Signals from CVEs in this product scope (89 CVEs).

Media Mentions

Signals from CVEs in this product scope (89 CVEs).

Top CNAs Publishing CVEs For Websphere Mq

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.1.126.80.6%00
9.1.0.027.20.9%00
9.0.455.81.6%00
9.0.3.017.80.4%00
9.0.385.11.2%00
9.0.2.017.80.4%00
9.0.2125.61.2%00
9.0.1.017.80.4%00
9.0.1135.51.1%00
9.0.0.246.21.7%00
9.0.0.1105.51.1%00
9.0.0.035.80.9%00
9.0.016.51.4%00
9.0105.51.1%00
8.0.0.836.11.6%00
8.0.0.775.51.2%00
8.0.0.6115.81.2%00
8.0.0.5155.51.1%00
8.0.0.4205.20.9%00
8.0.0.3205.11.0%00