Known vulnerabilities in IBM MQ Appliance - page 6

Software CPE: cpe:2.3:a:ibm_corporation:ibm_mq_appliance:*:*:*:*:*:*:*:*
Total vulnerabilities: 122
Public exploits: 9
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting IBM MQ Appliance IBM MQ Appliance is affected by 122 known vulnerabilities: 12 high, 67 medium, 43 low Critical High Medium Low

Vulnerabilities (122)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU72683 - Improper input validation
CVE-2022-43902
CWE-20 Medium
No
No
9.2.0.8, 9.2.5.4, 9.3.0.2, 9.3.1.1 01.03.2023 SB2023030127
SB2023030140
SB2023060819
#VU69431 - Improper Privilege Management
CVE-2020-35513
CWE-269 Low
No
No
9.2.0.7, 9.2.5.2 19.11.2022 SB2022111901
SB2022121922
SB2023010608
and 4 more
#VU69209 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-34165
CWE-444 Medium
No
No
9.2.0.6, 9.2.5.3, 9.3.0.1, 9.3.1 10.11.2022 SB2022111029
SB2022111104
SB2022111409
and 58 more
#VU68718 - Use After Free
CVE-2022-43680
CWE-416 Medium
No
No
9.3.0.5, 9.3.2.1 25.10.2022 SB2022102560
SB2022102566
SB2022103010
and 99 more
#VU68438 - Improper input validation
CVE-2022-21626
CWE-20 Medium
No
No
9.2.0.7, 9.2.5.4, 9.3.0.2, 9.3.1 18.10.2022 SB2022101901
SB2022101902
SB2022102012
and 157 more
#VU67655 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-31774
CWE-79 Medium
No
No
9.2.0.6, 9.2.5.2, 9.3.0.1 26.09.2022 SB2022092639
SB2022092640
#VU66858 - Cross-Site Request Forgery (CSRF)
CVE-2022-31773
CWE-352 Medium
No
No
9.2.0.7, 9.2.5.4 30.08.2022 SB2022083028
SB2023011270
#VU65845 - Authentication Bypass by Spoofing
CVE-2022-22476
CWE-290 Medium
No
No
9.2.0.6, 9.2.5.2, 9.3.0.1 28.07.2022 SB2022072816
SB2022080903
SB2022082228
and 29 more
#VU64079 - Missing release of memory after effective lifetime
CVE-2022-1012
CWE-401 Medium
No
No
9.3.0.2, 9.3.1 08.06.2022 SB2022060827
SB2022061417
SB2022062437
and 75 more
#VU63881 - Security Features
CVE-2022-31744
CWE-254 Medium
No
No
9.2.0.6, 9.2.5.2, 9.3.0.1 31.05.2022 SB2022053116
SB2022061323
SB2022062901
and 32 more
#VU63668 - Exposure of sensitive information to an unauthorized actor
CVE-2021-45485
CWE-200 Medium
No
No
9.3.0.2, 9.3.1 25.05.2022 SB2022022237
SB2022062928
SB2022062931
and 26 more
#VU63577 - Exposure of sensitive information to an unauthorized actor
CVE-2021-45486
CWE-200 Medium
No
No
9.3.0.2, 9.3.1 24.05.2022 SB2022062928
SB2022062931
SB2022070643
and 26 more
#VU61799 - Out-of-bounds write
CVE-2020-36518
CWE-787 Medium
No
No
9.2.5 01.04.2022 SB2022040113
SB2022040114
SB2022040115
and 147 more
#VU61669 - Exposure of sensitive information to an unauthorized actor
CVE-2022-0155
CWE-200 Low
No
No
9.2.0.6, 9.2.5 28.03.2022 SB2022032840
SB2022032843
SB2022071505
and 32 more
#VU61668 - Exposure of sensitive information to an unauthorized actor
CVE-2022-0536
CWE-200 Low
No
No
9.2.0.6, 9.2.5 28.03.2022 SB2022032841
SB2022032843
SB2022042561
and 27 more
#VU49150 - Use of Insufficiently Random Values
CVE-2020-25705
CWE-330 Medium
Available
No
9.2.0.7, 9.2.5.4 17.11.2020 SB2020111734
SB2020122413
SB2021031802
and 24 more
#VU26648 - Use After Free
CVE-2019-19527
CWE-416 Low
No
No
9.2.0.6 07.04.2020 SB2019120322
SB2020040728
SB2020073031
and 8 more
#VU21716 - Double Free
CVE-2017-18595
CWE-415 Low
No
No
9.2.0.6 11.10.2019 SB2019101101
SB2019101102
SB2020052210
and 9 more
#VU20806 - Out-of-bounds read
CVE-2018-19985
CWE-125 Low
No
No
9.2.0.6 03.09.2019 SB2019032120
SB2019020623
SB2022071414
and 2 more
#VU16628 - Memory corruption
CVE-2018-20169
CWE-119 Low
No
No
9.2.0.6 19.12.2018 SB2018121907
SB2020070103
SB2019020623
and 6 more


Showing elements 101 - 120 out of 122