Known vulnerabilities in IBM MQ 9.4.0.23
Vendor:
IBM Corporation
Software:
IBM MQ
Version:
9.4.0.23
Software CPE:
cpe:2.3:a:ibm_corporation:ibm_mq:*:*:*:*:*:*:*:*
Website:
https://www.ibm.com/us-en
Total vulnerabilities:
30
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.2
Vulnerabilities by Severity
9.1.0.38
9.2.0.44
9.3.0.42
9.4.0.26
10.0.0.5
9.4.3.0
9.4.0.24
9.4.0.23
9.4.0.22
10.0.0.0
9.4.0.25
9.3.0.41
9.2.0.43
9.1.0.37
9.4.0.21
9.3.0.40
9.2.0.42
9.1.0.36
9.4.5.1
9.4.0.19
9.4.0.18
9.4.0.20
9.3.0.37
9.1.0.34
9.2.0.41
9.4.4.0
9.4.0.16
9.4.0.15
9.4.0.14
9.4.0.13
9.4.0.12
9.4.0.11
9.4.0.9
9.4.0.8
9.3.0.35
9.3.0.34
9.3.0.33
9.3.0.32
9.3.0.31
9.3.0.30
9.3.0.29
9.3.0.28
9.2.0.40
9.2.0.39
9.2.0.38
9.2.0.37
9.2.0.36
9.2.0.35
9.2.0.34
9.2.0.33
9.2.0.32
9.1.0.28
9.1.0.29
9.1.0.30
9.1.0.31
9.1.0.32
9.1.0.33
9.3.0.36
9.4.0.17
9.4.4.1
9.4.0.10
9.3.0.27
9.2.0.31
9.1.0.27
9.4.2
8.0.0.16 SU2
1.8.2 CD
1.3.4 EUS
9.2.0.30
9.2.0.29
9.2.0.24
9.2.0.23
9.2.0.19
9.2.0.18
9.2.0.17
9.2.0.14
9.2.0.13
9.2.0.12
9.3.0.24
9.3.0.23
9.3.0.22
9.3.0.19
9.3.0.18
9.3.0.14
9.3.0.13
9.3.0.12
9.3.0.9
9.3.0.8
9.3.0.7
9.4.0.4
9.4.0.3
9.4.0.2
9.4.0.1
9.4.0.0
9.4.1.1
9.3.0.26
9.1.0.26
9.4.0.7
9.4.0.6
9.3.0.25
9.2.0.28
9.1.0.24
9.4.1
9.4.0.5
9.3.0.21
9.2.0.27
9.1.0.23
9.0.0.27
9.3.5.2
9.3.0.20 FixPack
9.0.0.25
9.0.0.26
9.2.0.26
9.4
9.3.0.20
9.1.0.22
9.3.5.1
9.3.0.17
9.2.0.25
9.1.0.21
9.0.0.24
9.3.0
9.3.0.16
9.3.5
9.2.0.22
9.1.0.20
9.0.0.23
7.5.0.9
9.2
9.1
9.0
9.3.4.1
9.3.0.15
9.2.0.21
9.1.0.19
9.0.0.22
9.3.4
9.3.0.11
9.2.0.20
9.1.0.18
9.0.0.21
9.3.3.1
9.3.0.10
9.2.0.16
9.1.0.17
9.0.0.19
9.3.3
9.3.0.6
9.2.0.15
9.1.0.16
9.0.0.18
9.3.0.5-r3
9.3.2.1
9.0.0.17
9.2.0.11
9.3.0.5
9.0.0.15
9.3.2.0
9.3.0.3
9.3.0.4
9.0.0.16
9.3.0.0
9.2.0.10
9.2.0.9
9.2.0.8
9.1.0.13
9.0.0.14
9.3.1.1
9.3.1.0
9.3.0.2
9.2.0.7
9.3.1
9.3.0.1
9.1.0.12
-
9.3
9.2.0.6
9.2.0.1
9.2.0.2
9.2.0.3
9.2.0.4
9.2.4 CD
9.2.0.5
9.2.5 CD
9.2 IT40099
9.1.0.11
9.1.0.10
9.1.0.9
9.1.0.8
9.1.0.7
9.1.0.6
9.1.0.5
9.1.0.4
9.1.0.3
9.1.0.2
9.0.0.13
9.0.0.12
9.0.0.11
9.0.0.10
9.0.0.9
9.0.0.8
9.0.0.7
9.0.0.6
9.0.0.0
8.0.0.16
8.0.0.15
8.0.0.14
8.0.0.13
8.0.0.12
8.0.0.11
9.2.1.0
9.2.0.0
9.1.5.0
9.1.3.0
9.1.2.0
9.1.1.0
9.0.5.0
9.2.2.0
9.1.4.0
9.1.1
9.1.0.1
5.3.1.15
9.1.0.0
9.0.0.5
9.0.0.4
8.0.0.10
7.1.0.9
8.0.0.9
7.0.1.14
7.0.1.13
9.0.0.3
9.0.4
9.0.0.2
8.0.0.8
8.0.0.7
7.5.0.8
9.0.0.1
9.0.5
8.0.0.6
8.0.0.5
7.5.0.7
7.5.0.6
7.1.0.8
7.1.0.7
9.0.3
9.0.2
9.0.1
9.0.0
8.0.0.4
7.1.0.6
7.5.0.5
8.0.0.3
8.0.0.2
8.0
8.0.0.1
7.0.1.12
7.0.1.11
7.1.0.5
7.5.0.4
8.0.0.0
7.5.0.3
7.1.0.3
7.1.0.4
7.5.0.2
7.0.1.9
7.5.0.1
7.1.0.2
7.1.0.1
7.0.1.10
7.0.4
7.0.4.0
7.0.2.2
7.0.2.0
7.0.1.6
7.0.1.7
7.5
7.0.1.5
7.1
7.0.1.8
7.0.1.4
6.0.2.9
6.0.2.8
7.0.1.2
7.0.1.3
7.0.1
7.0.0
7.0.1.1
7.0.1.0
7.0.0.0
6.0.2.7
6.0.2.10
7.0.0.2
6.0.2.5
6.0.2.6
6.0.1.0
6.0.2.1
6.0.0.0
6.0.1.1
7.0.0.1
6.0.2.3
7.0
6.0.2.2
6.0.2.4
5.1
5.3.1
6
5.3
6.0.2.0
6.0
Vulnerabilities (30)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU139055 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2026-8646 |
CWE-444 | High | 9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26, 10.0.0.5 | 22.07.2026 |
SB2026072215 SB2026072219 SB2026072328 and 19 more |
||
| #VU139054 - Resource exhaustion CVE-2026-9320 |
CWE-400 | Medium | 9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26, 10.0.0.5 | 22.07.2026 |
SB2026072214 SB2026072219 SB2026072328 and 19 more |
||
| #VU137314 - Resource exhaustion CVE-2026-9071 |
CWE-400 | Low | 9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26, 10.0.0.5 | 10.07.2026 |
SB2026071036 SB2026071037 SB2026072219 and 18 more |
||
| #VU136794 - Resource exhaustion CVE-2026-9171 |
CWE-400 | Medium | 9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26, 10.0.0.5 | 02.07.2026 |
SB2026070280 SB2026070646 SB2026070880 and 17 more |
||
| #VU135124 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2026-11541 |
CWE-444 | High | 9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26, 10.0.0.5 | 24.06.2026 |
SB2026062445 SB2026062950 SB2026063026 and 21 more |
||
| #VU134270 - Use After Free CVE-2026-45447 |
CWE-416 | High | 9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26, 10.0.0.5 | 10.06.2026 |
SB20260610118 SB20260610119 SB20260610122 and 46 more |
||
| #VU134271 - Improper input validation CVE-2026-34182 |
CWE-20 | High | 9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26, 10.0.0.5 | 10.06.2026 |
SB20260610118 SB20260610119 SB20260610122 and 23 more |
||
| #VU134272 - Allocation of Resources Without Limits or Throttling CVE-2026-34183 |
CWE-770 | Medium | 9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26, 10.0.0.5 | 10.06.2026 |
SB20260610118 SB20260610119 SB20260610123 and 12 more |
||
| #VU134274 - NULL Pointer Dereference CVE-2026-42764 |
CWE-476 | Medium | 9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26, 10.0.0.5 | 10.06.2026 |
SB20260610118 SB20260610119 SB20260610123 and 13 more |
||
| #VU134275 - Improper Initialization CVE-2026-45445 |
CWE-665 | Low | 9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26, 10.0.0.5 | 10.06.2026 |
SB20260610118 SB20260610119 SB20260610123 and 21 more |
||
| #VU134276 - Heap-based Buffer Overflow CVE-2026-7383 |
CWE-122 | Low | 9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26, 10.0.0.5 | 10.06.2026 |
SB20260610118 SB20260610119 SB20260610122 and 34 more |
||
| #VU134277 - Out-of-bounds read CVE-2026-9076 |
CWE-125 | Medium | 9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26, 10.0.0.5 | 10.06.2026 |
SB20260610118 SB20260610119 SB20260610122 and 35 more |
||
| #VU134278 - Out-of-bounds read CVE-2026-34180 |
CWE-125 | Medium | 9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26, 10.0.0.5 | 10.06.2026 |
SB20260610118 SB20260610119 SB20260610122 and 35 more |
||
| #VU134279 - Improper input validation CVE-2026-34181 |
CWE-20 | Medium | 9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26, 10.0.0.5 | 10.06.2026 |
SB20260610118 SB20260610119 SB20260610123 and 13 more |
||
| #VU134281 - NULL Pointer Dereference CVE-2026-42766 |
CWE-476 | Medium | 9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26, 10.0.0.5 | 10.06.2026 |
SB20260610118 SB20260610119 SB20260610122 and 36 more |
||
| #VU134282 - NULL Pointer Dereference CVE-2026-42767 |
CWE-476 | Medium | 9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26, 10.0.0.5 | 10.06.2026 |
SB20260610118 SB20260610119 SB20260610122 and 23 more |
||
| #VU134283 - Observable discrepancy CVE-2026-42768 |
CWE-203 | Medium | 9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26, 10.0.0.5 | 10.06.2026 |
SB20260610118 SB20260610119 SB20260610123 and 17 more |
||
| #VU134284 - Improper Certificate Validation CVE-2026-42769 |
CWE-295 | Low | 9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26, 10.0.0.5 | 10.06.2026 |
SB20260610118 SB20260610119 SB20260610123 and 12 more |
||
| #VU134285 - Improper input validation CVE-2026-42770 |
CWE-20 | Medium | 9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26, 10.0.0.5 | 10.06.2026 |
SB20260610118 SB20260610119 SB20260610123 and 20 more |
||
| #VU134287 - Improper Verification of Cryptographic Signature CVE-2026-45446 |
CWE-347 | Medium | 9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26, 10.0.0.5 | 10.06.2026 |
SB20260610118 SB20260610119 SB20260610123 and 18 more |
Showing elements 1 - 20 out of 30