Known vulnerabilities in IBM MQ Appliance - page 2

Software CPE: cpe:2.3:a:ibm_corporation:ibm_mq_appliance:*:*:*:*:*:*:*:*
Total vulnerabilities: 122
Public exploits: 9
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting IBM MQ Appliance IBM MQ Appliance is affected by 122 known vulnerabilities: 12 high, 67 medium, 43 low Critical High Medium Low

Vulnerabilities (122)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU130954 - Out-of-bounds read
CVE-2026-6918
CWE-125 Medium
No
No
9.4.0.25, 9.4.5.2 11.05.2026 SB2026051152
SB20260528261
SB2026060168
and 12 more
#VU126759 - Improper input validation
CVE-2026-34282
CWE-20 Medium
No
No
9.4.0.25, 9.4.5.2 22.04.2026 SB20260422123
SB20260422124
SB20260422125
and 37 more
#VU126761 - Improper input validation
CVE-2026-22021
CWE-20 Medium
No
No
9.4.0.25, 9.4.5.2 22.04.2026 SB20260422123
SB20260422124
SB20260422125
and 81 more
#VU126762 - Improper input validation
CVE-2026-22013
CWE-20 Medium
No
No
9.4.0.25, 9.4.5.2 22.04.2026 SB20260422123
SB20260422124
SB20260422125
and 78 more
#VU126763 - Improper input validation
CVE-2026-22008
CWE-20 Low
No
No
9.4.0.25, 9.4.5.2 22.04.2026 SB20260422123
SB2026050683
SB20260513117
and 20 more
#VU126764 - Improper input validation
CVE-2026-22018
CWE-20 Low
No
No
9.4.0.25, 9.4.5.2 22.04.2026 SB20260422123
SB20260422124
SB20260422125
and 78 more
#VU126765 - Improper input validation
CVE-2026-22007
CWE-20 Low
No
No
9.4.0.25, 9.4.5.2 22.04.2026 SB20260422123
SB20260422124
SB20260422125
and 78 more
#VU126766 - Improper input validation
CVE-2026-34268
CWE-20 Low
No
No
9.4.0.25, 9.4.5.2 22.04.2026 SB20260422123
SB20260422124
SB20260422125
and 78 more
#VU125981 - Exposure of sensitive information to an unauthorized actor
CVE-2026-40895
CWE-200 Medium
No
No
9.4.0.25, 9.4.5.2 14.04.2026 SB20260414106
SB2026062434
SB20260625284
and 16 more
#VU124831 - Weak Password Requirements
CVE-2025-14917
CWE-521 Low
No
No
9.4.0.21, 9.4.5.1 02.04.2026 SB2026040252
SB2026040327
SB2026040328
and 18 more
#VU124014 - Resource Management Errors
CVE-2026-3497
CWE-399 Low
No
No
9.4.0.21, 9.4.5.1 13.03.2026 SB2026031837
SB2026031838
SB2026031839
and 19 more
#VU123884 - Integer overflow
CVE-2026-23865
CWE-190 Medium
No
No
9.4.0.25, 9.4.5.2 11.03.2026 SB2026031140
SB2026031141
SB2026031523
and 51 more
#VU123539 - Use After Free
CVE-2026-23231
CWE-416 Low
No
No
9.4.0.21, 9.4.5.1 04.03.2026 SB2026030454
SB2026040601
SB2026040602
and 33 more
#VU123327 - Use of a Broken or Risky Cryptographic Algorithm
CVE-2025-14456
CWE-327 High
No
No
9.4.5.0 27.02.2026 SB2026022729
#VU123325 - Authentication Bypass by Primary Weakness
CVE-2026-1713
CWE-305 Low
No
No
9.4.0.20, 9.4.5.0 27.02.2026 SB2026022727
#VU122869 - Use After Free
CVE-2026-23193
CWE-416 Low
No
No
9.4.0.21, 9.4.5.1 16.02.2026 SB2026021653
SB2026021911
SB2026031305
and 34 more
#VU121727 - Improper input validation
CVE-2026-21945
CWE-20 Medium
No
No
9.4.0.20, 9.4.5.1 20.01.2026 SB20260120152
SB20260120153
SB20260120154
and 96 more
#VU120834 - Integer overflow
CVE-2022-50865
CWE-190 Low
No
No
9.4.0.20, 9.4.5.1 30.12.2025 SB20251230279
SB2026020210
SB2026020211
and 13 more
#VU119901 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2025-12635
CWE-79 Medium
No
No
9.4.0.20, 9.4.5.0 12.12.2025 SB2025121283
SB2025121517
SB2025121518
and 42 more
#VU117276 - Improper input validation
CVE-2025-39971
CWE-20 Low
No
No
9.4.0.20, 9.4.5.0 15.10.2025 SB20251015124
SB2025102476
SB2025102477
and 57 more


Showing elements 21 - 40 out of 122