Known vulnerabilities in IBM MQ Appliance - page 5
Vendor:
IBM Corporation
Software:
IBM MQ Appliance
Software CPE:
cpe:2.3:a:ibm_corporation:ibm_mq_appliance:*:*:*:*:*:*:*:*
Website:
https://www.ibm.com/us-en
Total vulnerabilities:
122
Public exploits:
9
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
10.0.0.0
10.0.0.1
9.4.0.24
9.4.0.23
9.4.0.22
9.4.5.3
10.0.0.5
9.4.0.26
9.4.3.0
9.4.0.25
9.4.5.2
9.4.0.19
9.4.0.18
9.4.0.21
9.4.5.1
9.4.4.0
9.4.4.1
9.4.1.1
9.4.1.0
9.4.0.17
9.4.0.16
9.4.0.15
9.4.0.14
9.4.0.13
9.4.0.12
9.4.0.9
9.4.0.8
9.4.0.7
9.4.0.4
9.4.0.3
9.4.0.2
9.4.0.1
9.4.0.0
9.4.5.0
9.4.0.20
9.4.2.1
9.4.0.11
9.3.0.28
9.4.2
9.4.0.10
9.3.0.27
9.2.5 CD
9.4.0.6
9.3.0.25
9.3.0.21
9.4.0.5
9.3.5.2
9.3.0.20
9.3.5.1
9.3.0.17
9.3.5
9.3.0.16
9.3.4.1
9.3.0.15
9.3.4
9.2.0.20
9.2.5 CSU03
9.2.5-CSU02
9.3.3.1
9.3.0.10
9.2.0.16
9.2.5.8
9.2.0.15
9.3.3
9.3.0.6
9.2.0.11
9.2.0.10
9.2.0.9
9.2.5.7
9.2.5.6
9.2.5.5
9.2.5.1
9.3.2.1
9.3.0.5
9.3.0.4
9.3.0.3
9.3.2
9.3.1.1
9.2.0.8
9.2.5.4
9.2.0.7
9.3.0.2
9.3.1
9.2.5.3
9.2.5.2
9.3.0.1
9.3.0.0
9.2.0.6
9.2.5
9.2.4
9.2.3
9.2.2
9.2.1
9.2.0.5
9.2.0.4
9.2.0.3
9.2.0.2
9.2.0.1
9.2.0.0
Vulnerabilities (122)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU82030 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2022-32750 |
CWE-79 | Medium | 9.2.0.6, 9.2.5-CSU02, 9.3.0.2, 9.3.1.1 | 16.10.2023 |
SB2023101617 |
||
| #VU82028 - Insufficient Session Expiration CVE-2022-40230 |
CWE-613 | Low | 9.2.5 CSU03, 9.3.0.2, 9.3.1.1 | 16.10.2023 |
SB2023101616 |
||
| #VU82013 - Improper Restriction of XML External Entity Reference ('XXE') CVE-2022-31775 |
CWE-611 | High | 9.2.0.6, 9.2.5-CSU02, 9.3.0.2, 9.3.1.1 | 16.10.2023 |
SB2023101602 SB2022122219 |
||
| #VU80404 - Improper input validation CVE-2023-28513 |
CWE-20 | Medium | 9.2.0.15, 9.2.5.8, 9.3.0.6, 9.3.3 | 04.09.2023 |
SB2023090455 SB2023092119 SB2023092225 and 1 more |
||
| #VU76651 - Resource Management Errors CVE-2023-2650 |
CWE-399 | Medium | 9.2.0.16, 9.3.0.10, 9.3.3.1 | 30.05.2023 |
SB2023053040 SB2023053044 SB2023053045 and 131 more |
||
| #VU76487 - Inadequate Encryption Strength CVE-2023-32342 |
CWE-326 | Medium | 9.2.0.15, 9.2.5.8, 9.3.0.6, 9.3.3 | 24.05.2023 |
SB2023052446 SB2023060817 SB2023061605 and 25 more |
||
| #VU75593 - Improper input validation CVE-2023-26285 |
CWE-20 | Medium | 9.2.0.11, 9.2.5.7, 9.3.0.5, 9.3.2.1 | 28.04.2023 |
SB2023042850 SB2023042853 SB2023071403 and 2 more |
||
| #VU75590 - Improper input validation CVE-2022-43919 |
CWE-20 | Medium | 9.2.0.10, 9.2.5.7, 9.3.0.5, 9.3.2 | 28.04.2023 |
SB2023042847 SB2023042852 SB2023051921 and 2 more |
||
| #VU75508 - Exposure of sensitive information to an unauthorized actor CVE-2023-30441 |
CWE-200 | Medium | 9.2.0.7, 9.2.5.3, 9.3.0.1 | 26.04.2023 |
SB2023042618 SB2023042749 SB2023050107 and 41 more |
||
| #VU75260 - Improper input validation CVE-2023-21930 |
CWE-20 | Medium | 9.2.0.16, 9.3.0.10, 9.3.3.1 | 18.04.2023 |
SB20230418166 SB20230418167 SB2023041942 and 191 more |
||
| #VU75261 - Improper input validation CVE-2023-21967 |
CWE-20 | Medium | 9.2.0.16, 9.3.0.10, 9.3.3.1 | 18.04.2023 |
SB20230418166 SB20230418167 SB2023041942 and 189 more |
||
| #VU72432 - Heap-based Buffer Overflow CVE-2022-48303 |
CWE-122 | High | 9.3.0.6, 9.3.3 | 21.02.2023 |
SB2023022105 SB2023022111 SB2023022112 and 72 more |
||
| #VU72427 - Allocation of Resources Without Limits or Throttling CVE-2023-24998 |
CWE-770 | Medium | 9.2.0.15, 9.2.5.8, 9.3.0.6, 9.3.3 | 20.02.2023 |
SB2023022046 SB2023022047 SB2023030917 and 203 more |
||
| #VU71996 - Double Free CVE-2022-4450 |
CWE-415 | Medium | 9.2.0.11, 9.2.5.7, 9.3.0.5, 9.3.2.1 | 07.02.2023 |
SB2023020742 SB2023020748 SB2023020771 and 180 more |
||
| #VU71995 - Use After Free CVE-2023-0215 |
CWE-416 | Medium | 9.2.0.11, 9.2.5.7, 9.3.0.5, 9.3.2.1 | 07.02.2023 |
SB2023020742 SB2023020747 SB2023020748 and 209 more |
||
| #VU71993 - Information Exposure Through Timing Discrepancy CVE-2022-4304 |
CWE-208 | Medium | 9.2.0.11, 9.2.5.7, 9.3.0.5, 9.3.2.1 | 07.02.2023 |
SB2023020742 SB2023020748 SB2023020767 and 222 more |
||
| #VU71992 - Type confusion CVE-2023-0286 |
CWE-843 | High | 9.2.0.11, 9.2.5.7, 9.3.0.5, 9.3.2.1 | 07.02.2023 |
SB2023020742 SB2023020747 SB2023020748 and 223 more |
||
| #VU68858 - Off-by-one Error CVE-2021-46848 |
CWE-193 | Medium | 9.3.0.5, 9.3.2.1 | 31.10.2022 |
SB2022103141 SB2022103142 SB2022103143 and 84 more |
||
| #VU68829 - Resource Management Errors CVE-2022-40304 |
CWE-399 | Medium | 9.3.0.5, 9.3.2.1 | 30.10.2022 |
SB2022103005 SB2022103006 SB2022103007 and 90 more |
||
| #VU68828 - Integer overflow CVE-2022-40303 |
CWE-190 | High | 9.3.0.5, 9.3.2.1 | 30.10.2022 |
SB2022103005 SB2022103006 SB2022103007 and 88 more |
Showing elements 81 - 100 out of 122