Known vulnerabilities in IBM MQ Appliance

Software CPE: cpe:2.3:a:ibm_corporation:ibm_mq_appliance:*:*:*:*:*:*:*:*
Total vulnerabilities: 104
Public exploits: 5
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting IBM MQ Appliance IBM MQ Appliance is affected by 104 known vulnerabilities: 8 high, 58 medium, 38 low Critical High Medium Low

Vulnerabilities (104)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU130954 - Out-of-bounds read
CVE-2026-6918
CWE-125 Medium
No
No
9.4.0.25, 9.4.5.2 11.05.2026 SB2026051152
SB20260528261
SB2026060168
and 10 more
#VU126758 - Improper input validation
CVE-2026-22016
CWE-20 Medium
No
No
9.4.0.25, 9.4.5.2 22.04.2026 SB20260422123
SB20260422124
SB20260422125
and 71 more
#VU126759 - Improper input validation
CVE-2026-34282
CWE-20 Medium
No
No
9.4.0.25, 9.4.5.2 22.04.2026 SB20260422123
SB20260422124
SB20260422125
and 31 more
#VU126761 - Improper input validation
CVE-2026-22021
CWE-20 Medium
No
No
9.4.0.25, 9.4.5.2 22.04.2026 SB20260422123
SB20260422124
SB20260422125
and 72 more
#VU126762 - Improper input validation
CVE-2026-22013
CWE-20 Medium
No
No
9.4.0.25, 9.4.5.2 22.04.2026 SB20260422123
SB20260422124
SB20260422125
and 70 more
#VU126763 - Improper input validation
CVE-2026-22008
CWE-20 Low
No
No
9.4.0.25, 9.4.5.2 22.04.2026 SB20260422123
SB2026050683
SB20260513117
and 15 more
#VU126764 - Improper input validation
CVE-2026-22018
CWE-20 Low
No
No
9.4.0.25, 9.4.5.2 22.04.2026 SB20260422123
SB20260422124
SB20260422125
and 70 more
#VU126765 - Improper input validation
CVE-2026-22007
CWE-20 Low
No
No
9.4.0.25, 9.4.5.2 22.04.2026 SB20260422123
SB20260422124
SB20260422125
and 70 more
#VU126766 - Improper input validation
CVE-2026-34268
CWE-20 Low
No
No
9.4.0.25, 9.4.5.2 22.04.2026 SB20260422123
SB20260422124
SB20260422125
and 70 more
#VU125981 - Exposure of sensitive information to an unauthorized actor
CVE-2026-40895
CWE-200 Medium
No
No
9.4.0.25, 9.4.5.2 14.04.2026 SB20260414106
SB2026062434
SB20260625284
and 7 more
#VU124831 - Weak Password Requirements
CVE-2025-14917
CWE-521 Low
No
No
9.4.0.21, 9.4.5.1 02.04.2026 SB2026040252
SB2026040327
SB2026040328
and 12 more
#VU124014 - Resource Management Errors
CVE-2026-3497
CWE-399 Low
No
No
9.4.0.21, 9.4.5.1 13.03.2026 SB2026031837
SB2026031838
SB2026031839
and 18 more
#VU123884 - Integer overflow
CVE-2026-23865
CWE-190 Medium
No
No
9.4.0.25, 9.4.5.2 11.03.2026 SB2026031140
SB2026031141
SB2026031523
and 45 more
#VU123539 - Use After Free
CVE-2026-23231
CWE-416 Low
No
No
9.4.0.21, 9.4.5.1 04.03.2026 SB2026030454
SB2026040601
SB2026040602
and 33 more
#VU123327 - Use of a Broken or Risky Cryptographic Algorithm
CVE-2025-14456
CWE-327 High
No
No
9.4.5.0 27.02.2026 SB2026022729
#VU122869 - Use After Free
CVE-2026-23193
CWE-416 Low
No
No
9.4.0.21, 9.4.5.1 16.02.2026 SB2026021653
SB2026021911
SB2026031305
and 34 more
#VU121727 - Improper input validation
CVE-2026-21945
CWE-20 Medium
No
No
9.4.0.20, 9.4.5.1 20.01.2026 SB20260120152
SB20260120153
SB20260120154
and 96 more
#VU120834 - Integer overflow
CVE-2022-50865
CWE-190 Low
No
No
9.4.0.20, 9.4.5.1 30.12.2025 SB20251230279
SB2026020210
SB2026020211
and 13 more
#VU119901 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2025-12635
CWE-79 Medium
No
No
9.4.0.20, 9.4.5.0 12.12.2025 SB2025121283
SB2025121517
SB2025121518
and 42 more
#VU95011 - Double Free
CVE-2024-41073
CWE-415 Low
No
No
9.4.0.25, 9.4.5.2 31.07.2024 SB2024073194
SB2024080967
SB2024080968
and 48 more


Showing elements 1 - 20 out of 104