<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – IBM MQ (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/ibm-mq.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/ibm-mq-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – IBM MQ (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:42 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2025-36128 – IBM MQ 9.1, 9.2, 9.3, 9.4 LTS and 9.3, 9.4 CD is vulnerable to a denial of servi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36128</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36128</guid>
    <pubDate>Thu, 16 Oct 2025 17:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-36128</strong></p>
  <p>IBM MQ 9.1, 9.2, 9.3, 9.4 LTS and 9.3, 9.4 CD is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations. By conducting slowloris-type attacks, a remote attacker could exploit this vulnerability to cause a denial of service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-772</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36128">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-0975 – IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD console could allow an authenticated...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0975</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0975</guid>
    <pubDate>Fri, 28 Feb 2025 03:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-0975</strong></p>
  <p>IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD console could allow an authenticated user to execute code due to improper neutralization of escape characters.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-150</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0975">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-40681 – IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow an aut...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-40681</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-40681</guid>
    <pubDate>Sat, 07 Sep 2024 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-40681</strong></p>
  <p>IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow an authenticated user in a specifically defined role, to bypass security restrictions and execute actions against the queue manager.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-40681">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-39742 – IBM MQ Operator 3.2.2 and IBM MQ Operator 2.0.24 could allow a user to bypass au...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-39742</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-39742</guid>
    <pubDate>Mon, 08 Jul 2024 14:15:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-39742</strong></p>
  <p>IBM MQ Operator 3.2.2 and IBM MQ Operator 2.0.24 could allow a user to bypass authentication under certain configurations due to a partial string comparison vulnerability.  IBM X-Force ID:  297169.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-187</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39742">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-31912 – IBM MQ 9.3 LTS and 9.3 CD could allow an authenticated user to escalate their pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-31912</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-31912</guid>
    <pubDate>Fri, 28 Jun 2024 18:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-31912</strong></p>
  <p>IBM MQ 9.3 LTS and 9.3 CD could allow an authenticated user to escalate their privileges under certain configurations due to incorrect privilege assignment.  IBM X-Force ID:  289894.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-31912">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-25015 – IBM MQ 9.2 LTS, 9.3 LTS, and 9.3 CD Internet Pass-Thru could allow a remote user...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-25015</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-25015</guid>
    <pubDate>Wed, 01 May 2024 17:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-25015</strong></p>
  <p>IBM MQ 9.2 LTS, 9.3 LTS, and 9.3 CD Internet Pass-Thru could allow a remote user to cause a denial of service by sending HTTP requests that would consume all available resources.  IBM X-Force ID:  281278.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-406</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-25015">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-25048 – IBM MQ Appliance 9.3 CD and LTS are vulnerable to a heap-based buffer overflow, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-25048</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-25048</guid>
    <pubDate>Sat, 27 Apr 2024 12:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-25048</strong></p>
  <p>IBM MQ Appliance 9.3 CD and LTS are vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote authenticated attacker could overflow a buffer and execute arbitrary code on the system or cause the server to crash.  IBM X-Force ID:  283137.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-25048">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-25016 – IBM MQ and IBM MQ Appliance 9.0, 9.1, 9.2, 9.3 LTS and 9.3 CD could allow a remo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-25016</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-25016</guid>
    <pubDate>Sun, 03 Mar 2024 04:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-25016</strong></p>
  <p>IBM MQ and IBM MQ Appliance 9.0, 9.1, 9.2, 9.3 LTS and 9.3 CD could allow a remote unauthenticated attacker to cause a denial of service due to incorrect buffering logic.  IBM X-Force ID:  281279.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-25016">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-26284 – IBM MQ Certified Container 9.3.0.1 through 9.3.0.3 and 9.3.1.0 through 9.3.1.1 c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-26284</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-26284</guid>
    <pubDate>Wed, 15 Mar 2023 18:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-26284</strong></p>
  <p>IBM MQ Certified Container 9.3.0.1 through 9.3.0.3 and 9.3.1.0 through 9.3.1.1 could allow authenticated users with the cluster to be granted administration access to the MQ console due to improper access controls.  IBM X-Force ID:  248417.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26284">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-22489 – IBM MQ 8.0, (9.0, 9.1, 9.2 LTS), and (9.1 and 9.2 CD) are vulnerable to an XML E...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-22489</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-22489</guid>
    <pubDate>Fri, 19 Aug 2022 19:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-22489</strong></p>
  <p>IBM MQ 8.0, (9.0, 9.1, 9.2 LTS), and (9.1 and 9.2 CD) are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 226339.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22489">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-39034 – IBM MQ 9.1 LTS is vulnerable to a denial of service attack caused by an issue wi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-39034</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-39034</guid>
    <pubDate>Thu, 17 Feb 2022 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-39034</strong></p>
  <p>IBM MQ 9.1 LTS is vulnerable to a denial of service attack caused by an issue within the channel process. IBM X-Force ID: 213964.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39034">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-38950 – IBM MQ on HPE NonStop 8.0.4 and 8.1.0 is vulnerable to a privilege escalation at...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38950</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38950</guid>
    <pubDate>Tue, 14 Dec 2021 17:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-38950</strong></p>
  <p>IBM MQ on HPE NonStop 8.0.4 and 8.1.0 is vulnerable to a privilege escalation attack when SharedBindingsUserId is set to effective. IBM X-ForceID: 211404.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38950">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-4938 – IBM MQ Appliance 9.1 and 9.2 is vulnerable to cross-site request forgery which c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4938</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4938</guid>
    <pubDate>Mon, 12 Jul 2021 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-4938</strong></p>
  <p>IBM MQ Appliance 9.1 and 9.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 191815.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4938">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-4682 – IBM MQ 7.5, 8.0, 9.0, 9.1, 9.2 LTS, and 9.2 CD could allow a remote attacker to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4682</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4682</guid>
    <pubDate>Thu, 28 Jan 2021 13:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-4682</strong></p>
  <p>IBM MQ 7.5, 8.0, 9.0, 9.1, 9.2 LTS, and 9.2 CD could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization of trusted data. An attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 186509.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4682">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-4766 – IBM MQ Internet Pass-Thru 2.1 and 9.2 could allow a remote user to cause a denia...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4766</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4766</guid>
    <pubDate>Fri, 22 Jan 2021 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-4766</strong></p>
  <p>IBM MQ Internet Pass-Thru 2.1 and 9.2 could allow a remote user to cause a denial of service by sending malformed MQ data requests which would consume all available resources. IBM X-Force ID: 188093.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4766">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-4870 – IBM MQ 9.2 CD and LTS are vulnerable to a denial of service attack caused by an ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4870</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4870</guid>
    <pubDate>Mon, 21 Dec 2020 18:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-4870</strong></p>
  <p>IBM MQ 9.2 CD and LTS are vulnerable to a denial of service attack caused by an error processing connecting applications. IBM X-Force ID: 190833.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4870">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-4375 – IBM MQ, IBM MQ Appliance, IBM MQ for HPE NonStop 8.0, 9.1 CD, and 9.1 LTS could ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4375</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4375</guid>
    <pubDate>Tue, 28 Jul 2020 12:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-4375</strong></p>
  <p>IBM MQ, IBM MQ Appliance, IBM MQ for HPE NonStop 8.0, 9.1 CD, and 9.1 LTS could allow an attacker to cause a denial of service due to a memory leak caused by an error creating a dynamic queue. IBM X-Force ID: 179080.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4375">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-4310 – IBM MQ and MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 C are vulnerabl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4310</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4310</guid>
    <pubDate>Tue, 16 Jun 2020 14:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-4310</strong></p>
  <p>IBM MQ and MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 C are vulnerable to a denial of service attack due to an error within the Data Conversion logic. IBM X-Force ID: 177081.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4310">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-4352 – IBM MQ on HPE NonStop 8.0.4 and 8.1.0 is vulnerable to a privilege escalation at...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4352</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4352</guid>
    <pubDate>Fri, 29 May 2020 13:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-4352</strong></p>
  <p>IBM MQ on HPE NonStop 8.0.4 and 8.1.0 is vulnerable to a privilege escalation attack when running in restricted mode. IBM X-Force ID: 178427.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4352">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-4762 – IBM MQ 9.0 and 9.1 is vulnerable to a denial of service attack due to an error i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-4762</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-4762</guid>
    <pubDate>Thu, 16 Apr 2020 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-4762</strong></p>
  <p>IBM MQ 9.0 and 9.1 is vulnerable to a denial of service attack due to an error in the Channel processing function. IBM X-Force ID: 173625.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-4762">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-4620 – IBM MQ Appliance 8.0 and 9.0 LTS could allow a local attacker to bypass security...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-4620</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-4620</guid>
    <pubDate>Tue, 28 Jan 2020 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-4620</strong></p>
  <p>IBM MQ Appliance 8.0 and 9.0 LTS could allow a local attacker to bypass security restrictions caused by improper validation of environment variables. IBM X-Force ID: 168863.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-4620">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-4227 – IBM MQ 8.0.0.4 - 8.0.0.12, 9.0.0.0 - 9.0.0.6, 9.1.0.0 - 9.1.0.2, and 9.1.0 - 9.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-4227</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-4227</guid>
    <pubDate>Fri, 04 Oct 2019 14:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-4227</strong></p>
  <p>IBM MQ 8.0.0.4 - 8.0.0.12, 9.0.0.0 - 9.0.0.6, 9.1.0.0 - 9.1.0.2, and 9.1.0 - 9.1.2 AMQP Listeners could allow an unauthorized user to conduct a session fixation attack due to clients not being disconnected as they should. IBM X-Force ID: 159352.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-384</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-4227">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-4294 – IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.6, 7.6.0.0 through 7.6.0.15 an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-4294</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-4294</guid>
    <pubDate>Tue, 20 Aug 2019 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-4294</strong></p>
  <p>IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.6, 7.6.0.0 through 7.6.0.15 and IBM MQ Appliance 8.0.0.0 through 8.0.0.12, 9.1.0.0 through 9.1.0.2, and 9.1.1 through 9.1.2 could allow a local attacker to execute arbitrary commands on the system, caused by a command injection vulnerability. IBM X-Force ID: 16188.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-4294">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-4055 – IBM MQ 8.0.0.0 through 8.0.0.10, 9.0.0.0 through 9.0.0.5, and 9.1.0.0 through 9...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-4055</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-4055</guid>
    <pubDate>Fri, 19 Apr 2019 17:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-4055</strong></p>
  <p>IBM MQ 8.0.0.0 through 8.0.0.10, 9.0.0.0 through 9.0.0.5, and 9.1.0.0 through 9.1.1 is vulnerable to a denial of service attack within the TLS key renegotiation function. IBM X-Force ID: 156564.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-4055">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-1318 – IBM MQ Appliance 8.0 and 9.0 could allow an authenticated messaging administrato...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1318</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1318</guid>
    <pubDate>Tue, 18 Jul 2017 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-1318</strong></p>
  <p>IBM MQ Appliance 8.0 and 9.0 could allow an authenticated messaging administrator to execute arbitrary commands on the system, caused by command execution. IBM X-Force ID: 125730.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1318">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-5879 – MQCLI on IBM MQ Appliance M2000 and M2001 devices allows local users to execute ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-5879</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-5879</guid>
    <pubDate>Fri, 02 Sep 2016 14:59:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-5879</strong></p>
  <p>MQCLI on IBM MQ Appliance M2000 and M2001 devices allows local users to execute arbitrary shell commands via a crafted (1) Disaster Recovery or (2) High Availability command.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-5879">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-1987 – IBM MQ Light before 1.0.0.2 allows remote attackers to cause a denial of service...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-1987</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-1987</guid>
    <pubDate>Mon, 03 Aug 2015 19:59:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-1987</strong></p>
  <p>IBM MQ Light before 1.0.0.2 allows remote attackers to cause a denial of service (disk consumption) via a crafted byte sequence in authentication data, a different vulnerability than CVE-2015-1956 and CVE-2015-1958.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-1987">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-1958 – IBM MQ Light before 1.0.0.2 allows remote attackers to cause a denial of service...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-1958</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-1958</guid>
    <pubDate>Mon, 03 Aug 2015 19:59:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-1958</strong></p>
  <p>IBM MQ Light before 1.0.0.2 allows remote attackers to cause a denial of service (disk consumption) via a crafted byte sequence in authentication data, a different vulnerability than CVE-2015-1956 and CVE-2015-1987.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-1958">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-1956 – IBM MQ Light before 1.0.0.2 allows remote attackers to cause a denial of service...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-1956</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-1956</guid>
    <pubDate>Mon, 03 Aug 2015 19:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-1956</strong></p>
  <p>IBM MQ Light before 1.0.0.2 allows remote attackers to cause a denial of service (disk consumption) via a crafted byte sequence in authentication data, a different vulnerability than CVE-2015-1958 and CVE-2015-1987.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-1956">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-1955 – IBM MQ Light before 1.0.0.2 allows remote attackers to cause a denial of service...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-1955</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-1955</guid>
    <pubDate>Mon, 03 Aug 2015 19:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-1955</strong></p>
  <p>IBM MQ Light before 1.0.0.2 allows remote attackers to cause a denial of service (CPU consumption) via a crafted byte sequence in authentication data.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-1955">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
