Known vulnerabilities in IBM MQ Appliance - page 4
Vendor:
IBM Corporation
Software:
IBM MQ Appliance
Software CPE:
cpe:2.3:a:ibm_corporation:ibm_mq_appliance:*:*:*:*:*:*:*:*
Website:
https://www.ibm.com/us-en
Total vulnerabilities:
104
Public exploits:
5
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
9.4.3.0
9.4.0.25
9.4.5.2
9.4.0.19
9.4.0.18
9.4.0.21
9.4.5.1
9.4.4.0
9.4.4.1
9.4.1.1
9.4.1.0
9.4.0.17
9.4.0.16
9.4.0.15
9.4.0.14
9.4.0.13
9.4.0.12
9.4.0.9
9.4.0.8
9.4.0.7
9.4.0.4
9.4.0.3
9.4.0.2
9.4.0.1
9.4.0.0
9.4.5.0
9.4.0.20
9.4.2.1
9.4.0.11
9.3.0.28
9.4.2
9.4.0.10
9.3.0.27
9.2.5 CD
9.4.0.6
9.3.0.25
9.3.0.21
9.4.0.5
9.3.5.2
9.3.0.20
9.3.5.1
9.3.0.17
9.3.5
9.3.0.16
9.3.4.1
9.3.0.15
9.3.4
9.2.0.20
9.2.5 CSU03
9.2.5-CSU02
9.3.3.1
9.3.0.10
9.2.0.16
9.2.5.8
9.2.0.15
9.3.3
9.3.0.6
9.2.0.11
9.2.0.10
9.2.0.9
9.2.5.7
9.2.5.6
9.2.5.5
9.2.5.1
9.3.2.1
9.3.0.5
9.3.0.4
9.3.0.3
9.3.2
9.3.1.1
9.2.0.8
9.2.5.4
9.2.0.7
9.3.0.2
9.3.1
9.2.5.3
9.2.5.2
9.3.0.1
9.3.0.0
9.2.0.6
9.2.5
9.2.4
9.2.3
9.2.2
9.2.1
9.2.0.5
9.2.0.4
9.2.0.3
9.2.0.2
9.2.0.1
9.2.0.0
Vulnerabilities (104)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU82657 - Permissions, Privileges, and Access Controls CVE-2023-46176 |
CWE-264 | Low | 9.3.4 | 01.11.2023 |
SB2023110133 |
||
| #VU82650 - Resource exhaustion CVE-2023-45177 |
CWE-400 | Low | 9.2.0.20, 9.3.0.10, 9.3.4 | 01.11.2023 |
SB2023110121 SB2023110306 SB2023110307 and 2 more |
||
| #VU82030 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2022-32750 |
CWE-79 | Medium | 9.2.0.6, 9.2.5-CSU02, 9.3.0.2, 9.3.1.1 | 16.10.2023 |
SB2023101617 |
||
| #VU82028 - Insufficient Session Expiration CVE-2022-40230 |
CWE-613 | Low | 9.2.5 CSU03, 9.3.0.2, 9.3.1.1 | 16.10.2023 |
SB2023101616 |
||
| #VU82013 - Improper Restriction of XML External Entity Reference ('XXE') CVE-2022-31775 |
CWE-611 | High | 9.2.0.6, 9.2.5-CSU02, 9.3.0.2, 9.3.1.1 | 16.10.2023 |
SB2023101602 SB2022122219 |
||
| #VU80404 - Improper input validation CVE-2023-28513 |
CWE-20 | Medium | 9.2.0.15, 9.2.5.8, 9.3.0.6, 9.3.3 | 04.09.2023 |
SB2023090455 SB2023092119 SB2023092225 and 1 more |
||
| #VU76651 - Resource Management Errors CVE-2023-2650 |
CWE-399 | Medium | 9.2.0.16, 9.3.0.10, 9.3.3.1 | 30.05.2023 |
SB2023053040 SB2023053044 SB2023053045 and 131 more |
||
| #VU76487 - Inadequate Encryption Strength CVE-2023-32342 |
CWE-326 | Medium | 9.2.0.15, 9.2.5.8, 9.3.0.6, 9.3.3 | 24.05.2023 |
SB2023052446 SB2023060817 SB2023061605 and 25 more |
||
| #VU75593 - Improper input validation CVE-2023-26285 |
CWE-20 | Medium | 9.2.0.11, 9.2.5.7, 9.3.0.5, 9.3.2.1 | 28.04.2023 |
SB2023042850 SB2023042853 SB2023071403 and 2 more |
||
| #VU75590 - Improper input validation CVE-2022-43919 |
CWE-20 | Medium | 9.2.0.10, 9.2.5.7, 9.3.0.5, 9.3.2 | 28.04.2023 |
SB2023042847 SB2023042852 SB2023051921 and 2 more |
||
| #VU75508 - Exposure of sensitive information to an unauthorized actor CVE-2023-30441 |
CWE-200 | Medium | 9.2.0.7, 9.2.5.3, 9.3.0.1 | 26.04.2023 |
SB2023042618 SB2023042749 SB2023050107 and 41 more |
||
| #VU75260 - Improper input validation CVE-2023-21930 |
CWE-20 | Medium | 9.2.0.16, 9.3.0.10, 9.3.3.1 | 18.04.2023 |
SB20230418166 SB20230418167 SB2023041942 and 191 more |
||
| #VU75261 - Improper input validation CVE-2023-21967 |
CWE-20 | Medium | 9.2.0.16, 9.3.0.10, 9.3.3.1 | 18.04.2023 |
SB20230418166 SB20230418167 SB2023041942 and 189 more |
||
| #VU72432 - Heap-based Buffer Overflow CVE-2022-48303 |
CWE-122 | High | 9.3.0.6, 9.3.3 | 21.02.2023 |
SB2023022105 SB2023022111 SB2023022112 and 72 more |
||
| #VU72427 - Allocation of Resources Without Limits or Throttling CVE-2023-24998 |
CWE-770 | Medium | 9.2.0.15, 9.2.5.8, 9.3.0.6, 9.3.3 | 20.02.2023 |
SB2023022046 SB2023022047 SB2023030917 and 202 more |
||
| #VU71996 - Double Free CVE-2022-4450 |
CWE-415 | Medium | 9.2.0.11, 9.2.5.7, 9.3.0.5, 9.3.2.1 | 07.02.2023 |
SB2023020742 SB2023020748 SB2023020771 and 180 more |
||
| #VU71995 - Use After Free CVE-2023-0215 |
CWE-416 | Medium | 9.2.0.11, 9.2.5.7, 9.3.0.5, 9.3.2.1 | 07.02.2023 |
SB2023020742 SB2023020747 SB2023020748 and 209 more |
||
| #VU71993 - Information Exposure Through Timing Discrepancy CVE-2022-4304 |
CWE-208 | Medium | 9.2.0.11, 9.2.5.7, 9.3.0.5, 9.3.2.1 | 07.02.2023 |
SB2023020742 SB2023020748 SB2023020767 and 222 more |
||
| #VU71992 - Type confusion CVE-2023-0286 |
CWE-843 | High | 9.2.0.11, 9.2.5.7, 9.3.0.5, 9.3.2.1 | 07.02.2023 |
SB2023020742 SB2023020747 SB2023020748 and 223 more |
||
| #VU68828 - Integer overflow CVE-2022-40303 |
CWE-190 | High | 9.3.0.5, 9.3.2.1 | 30.10.2022 |
SB2022103005 SB2022103006 SB2022103007 and 88 more |
Showing elements 61 - 80 out of 104