Websphere Mq
Vendor:
First CVE: Nov 20, 2007 · Active for 18 years
89
Total CVEs
More Total CVEs than 99% of tracked products
5.6
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
5.7
Avg CVSS
Higher Avg CVSS than 20% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Websphere Mq over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 20, 2007
18 years ago
Most Recent CVE
Sep 29, 2022
1,398 days ago
CVE Severity & Scoring
Websphere Mq89 CVEs
13%
64%
21%
All CVEs353,240 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local16 (18.0%)
Network38 (42.7%)
Unknown35 (39.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low38 (42.7%)
High16 (18.0%)
Unknown35 (39.3%)
User Interaction
None54 (60.7%)
Unknown35 (39.3%)
Required0 (0.0%)
Privileges Required
Low41 (46.1%)
High1 (1.1%)
None12 (13.5%)
Unknown35 (39.3%)
Top CVEs
Signals from CVEs in this product scope (89 CVEs).
89 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-3294MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in the Web Gateway component in IBM WebSphere MQ File Transfer Edition 7.0.4 and earlier, and WebSphere MQ - Managed File | Aug 17, 2012 | 6.8 | 32 | NO | YES |
CVE-2020-4682CRITICAL IBM MQ 7.5, 8.0, 9.0, 9.1, 9.2 LTS, and 9.2 CD could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization of trusted data. An attack | Jan 28, 2021 | 9.8 | 30 | NO | NO |
CVE-2009-0896HIGH Buffer overflow in the queue manager in IBM WebSphere MQ 6.x before 6.0.2.7 and 7.x before 7.0.1.0 allows remote attackers to execute arbitrary code via a crafted request. | Jun 3, 2009 | 10.0 | 29 | NO | NO |
CVE-2007-6044HIGH Multiple unspecified vulnerabilities in IBM WebSphere MQ 6.0 have unknown impact and remote attack vectors involving "memory corruption." NOTE: as of 20071116, the only disclosure | Nov 20, 2007 | 10.0 | 27 | NO | NO |
CVE-2012-2201HIGH IBM WebSphere MQ 7.1 is vulnerable to a denial of service, caused by an error when handling user ids. A remote attacker could exploit this vulnerability to bypass the security conf | Sep 29, 2022 | 7.5 | 26 | NO | NO |
CVE-2020-4310HIGH IBM MQ and MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 C are vulnerable to a denial of service attack due to an error within the Data Conversion logic. IBM X-Force ID: 17 | Jun 16, 2020 | 7.5 | 26 | NO | NO |
CVE-2018-1792HIGH IBM WebSphere MQ 8.0.0.0 through 8.0.0.10, 9.0.0.0 through 9.0.0.5, 9.0.1 through 9.0.5, and 9.1.0.0 could allow a local user to inject code that could be executed with root privil | Nov 13, 2018 | 7.8 | 26 | NO | NO |
CVE-2017-1337HIGH IBM WebSphere MQ 9.0.1 and 9.0.2 Java/JMS application can incorrectly transmit user credentials in plain text. IBM X-Force ID: 126245. | Jul 10, 2017 | 8.1 | 26 | NO | NO |
CVE-2018-1998HIGH IBM WebSphere MQ 8.0.0.0 through 9.1.1 could allow a local user to inject code that could be executed with root privileges. This is due to an incomplete fix for CVE-2018-1792. IBM | Mar 11, 2019 | 7.8 | 25 | NO | NO |
CVE-2018-1974HIGH IBM WebSphere 8.0.0.0 through 9.1.1 could allow an authenticated attacker to escalate their privileges when using multiplexed channels. IBM X-Force ID: 153915. | Mar 11, 2019 | 7.5 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (89 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
2.2% of CVEs· 85th percentile
Social Chatter
Signals from CVEs in this product scope (89 CVEs).
Media Mentions
Signals from CVEs in this product scope (89 CVEs).
Top CNAs Publishing CVEs For Websphere Mq
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.1.1 | 2 | 6.8 | 0.6% | 0 | 0 |
| 9.1.0.0 | 2 | 7.2 | 0.9% | 0 | 0 |
| 9.0.4 | 5 | 5.8 | 1.6% | 0 | 0 |
| 9.0.3.0 | 1 | 7.8 | 0.4% | 0 | 0 |
| 9.0.3 | 8 | 5.1 | 1.2% | 0 | 0 |
| 9.0.2.0 | 1 | 7.8 | 0.4% | 0 | 0 |
| 9.0.2 | 12 | 5.6 | 1.2% | 0 | 0 |
| 9.0.1.0 | 1 | 7.8 | 0.4% | 0 | 0 |
| 9.0.1 | 13 | 5.5 | 1.1% | 0 | 0 |
| 9.0.0.2 | 4 | 6.2 | 1.7% | 0 | 0 |
| 9.0.0.1 | 10 | 5.5 | 1.1% | 0 | 0 |
| 9.0.0.0 | 3 | 5.8 | 0.9% | 0 | 0 |
| 9.0.0 | 1 | 6.5 | 1.4% | 0 | 0 |
| 9.0 | 10 | 5.5 | 1.1% | 0 | 0 |
| 8.0.0.8 | 3 | 6.1 | 1.6% | 0 | 0 |
| 8.0.0.7 | 7 | 5.5 | 1.2% | 0 | 0 |
| 8.0.0.6 | 11 | 5.8 | 1.2% | 0 | 0 |
| 8.0.0.5 | 15 | 5.5 | 1.1% | 0 | 0 |
| 8.0.0.4 | 20 | 5.2 | 0.9% | 0 | 0 |
| 8.0.0.3 | 20 | 5.1 | 1.0% | 0 | 0 |