<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – IBM MQ</title>
  <link>https://cvedaily.com/pages/tags/ibm-mq.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/ibm-mq.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – IBM MQ</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:42 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-2607 – IBM MQ Operator SC2: v3.2.0 through 3.2.23CD:  v3.3.0, v3.4.0, v3.4.1, v3.5.0, v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2607</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2607</guid>
    <pubDate>Wed, 27 May 2026 14:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-2607</strong></p>
  <p>IBM MQ Operator SC2: v3.2.0 through 3.2.23CD:  v3.3.0, v3.4.0, v3.4.1, v3.5.0, v3.5.1 - v3.5.3, v3.6.0 - v3.6.4, v3.7.0 - v3.7.2, v3.8.0, v3.8.1, v3.9.0, v3.9.1LTS: v2.0.0 - 2.0.29 and IBM supplied MQ Advanced container images SC2: 9.4.0.6 through r1, 9.4.0.6-r2, 9.4.0.7-r1, 9.4.0.10-r1, 9.4.0.10-r2, 9.4.0.11-r1, 9.4.0.11-r2, 9.4.0.11-r3, 9.4.0.12-r1, 9.4.0.15-r1 - 9.4.0.15-r4, 9.4.0.16-r1, 9.4.0…</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2607">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1713 – IBM MQ 9.1.0.0 through 9.1.0.33 LTS, 9.2.0.0 through 9.2.0.40 LTS, 9.3.0.0 throu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1713</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1713</guid>
    <pubDate>Tue, 03 Mar 2026 21:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1713</strong></p>
  <p>IBM MQ 9.1.0.0 through 9.1.0.33 LTS, 9.2.0.0 through 9.2.0.40 LTS, 9.3.0.0 through 9.3.0.36 LTS, 9.30.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.17 LTS, and 9.4.0.0 through 9.4.4.1 CD</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-305</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1713">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-14456 – IBM MQ Appliance 9.4 CD through 9.4.4.0 to 9.4.4.1</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14456</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14456</guid>
    <pubDate>Tue, 03 Mar 2026 21:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-14456</strong></p>
  <p>IBM MQ Appliance 9.4 CD through 9.4.4.0 to 9.4.4.1</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14456">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-12755 – IBM MQ Operator (SC2 v3.2.0–3.8.1, LTS v2.0.0–2.0.29) and IBM‑supplied MQ Advanc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12755</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12755</guid>
    <pubDate>Tue, 17 Feb 2026 19:21:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-12755</strong></p>
  <p>IBM MQ Operator (SC2 v3.2.0–3.8.1, LTS v2.0.0–2.0.29) and IBM‑supplied MQ Advanced container images (across affected SC2, CD, and LTS 9.3.x–9.4.x releases) contain a vulnerability where log messages are not properly neutralized before being written to log files. This flaw could allow an unauthorized user to inject malicious data into MQ log entries, potentially leading to misleading logs, log man…</p>
  <p><strong>CVSS:</strong> 4.0 · <strong>CWE:</strong> CWE-117</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12755">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-36128 – IBM MQ 9.1, 9.2, 9.3, 9.4 LTS and 9.3, 9.4 CD is vulnerable to a denial of servi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36128</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36128</guid>
    <pubDate>Thu, 16 Oct 2025 17:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-36128</strong></p>
  <p>IBM MQ 9.1, 9.2, 9.3, 9.4 LTS and 9.3, 9.4 CD is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations. By conducting slowloris-type attacks, a remote attacker could exploit this vulnerability to cause a denial of service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-772</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36128">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-36100 – IBM MQ LTS 9.1.0.0 through 9.1.0.29, 9.2.0.0 through 9.2.0.36, 9.3.0.0 through 9...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36100</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36100</guid>
    <pubDate>Sun, 07 Sep 2025 01:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-36100</strong></p>
  <p>IBM MQ LTS 9.1.0.0 through 9.1.0.29, 9.2.0.0 through 9.2.0.36, 9.3.0.0 through 9.3.0.30 and 9.4.0.0 through 9.4.0.12 and IBM MQ CD 9.3.0.0 through 9.3.5.1 and 9.4.0.0 through 9.4.3.0  Java and JMS stores a password in client configuration files when trace is enabled which can be read by a local user.</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-260</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36100">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-36005 – IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 thr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36005</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36005</guid>
    <pubDate>Thu, 24 Jul 2025 15:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-36005</strong></p>
  <p>IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, 3.6.0, and MQ Operator SC2 3.2.0 through 3.2.13 Internet Pass-Thru could allow a malicious user to obtain sensitive information from another TLS session connection by the proxy to the same hostname and port due to improper certificate validation.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36005">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-33013 – IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 thr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-33013</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-33013</guid>
    <pubDate>Thu, 24 Jul 2025 15:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-33013</strong></p>
  <p>IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, 3.6.0, and MQ Operator SC2 3.2.0 through 3.2.13 Container could disclose sensitive information to a local user due to improper clearing of heap memory before release.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-244</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-33013">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-3631 – An IBM MQ 9.3 and 9.4 Client connecting to an MQ Queue Manager can cause a SIGSE...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3631</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3631</guid>
    <pubDate>Fri, 11 Jul 2025 19:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-3631</strong></p>
  <p>An IBM MQ 9.3 and 9.4 Client connecting to an MQ Queue Manager can cause a SIGSEGV in the AMQRMPPA channel process terminating it.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3631">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-36041 – IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 thr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36041</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36041</guid>
    <pubDate>Sun, 15 Jun 2025 13:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-36041</strong></p>
  <p>IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1 through 3.5.3, and MQ Operator SC2 3.2.0 through 3.2.12 Native HA CRR could be configured with a private key and chain other than the intended key which could disclose sensitive information or allow the attacker to perform unauthorized actions.</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36041">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-27365 – IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 thr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27365</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27365</guid>
    <pubDate>Thu, 01 May 2025 22:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-27365</strong></p>
  <p>IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, and MQ Operator SC2 3.2.0 through 3.2.10   Client connecting to a MQ Queue Manager can cause a SIGSEGV in the AMQRMPPA channel process terminating it.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27365">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-1333 – IBM MQ Container when used with the IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-1333</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-1333</guid>
    <pubDate>Thu, 01 May 2025 22:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-1333</strong></p>
  <p>IBM MQ Container when used with the IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, and MQ Operator SC2 3.2.0 through 3.2.10  and configured with Cloud Pak for Integration Keycloak could disclose sensitive information to a privileged user.</p>
  <p><strong>CVSS:</strong> 6.0 · <strong>CWE:</strong> CWE-214</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-1333">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-0985 – IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD 

stores potentially sensitive infor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0985</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0985</guid>
    <pubDate>Fri, 28 Feb 2025 17:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-0985</strong></p>
  <p>IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD   stores potentially sensitive information in environment variables that could be obtained by a local user.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-526</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0985">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-54175 – IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD 

could allow a local user to cause ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-54175</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-54175</guid>
    <pubDate>Fri, 28 Feb 2025 17:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-54175</strong></p>
  <p>IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD   could allow a local user to cause a denial of service due to an improper check for unusual or exceptional conditions.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-54175">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-23225 – IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow an authenticated user to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-23225</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-23225</guid>
    <pubDate>Fri, 28 Feb 2025 03:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-23225</strong></p>
  <p>IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow an authenticated user to cause a denial of service due to the improper handling of invalid headers sent to the queue.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-230</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23225">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-0975 – IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD console could allow an authenticated...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0975</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0975</guid>
    <pubDate>Fri, 28 Feb 2025 03:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-0975</strong></p>
  <p>IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD console could allow an authenticated user to execute code due to improper neutralization of escape characters.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-150</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0975">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-54173 – IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD reveals potentially sensitive inform...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-54173</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-54173</guid>
    <pubDate>Fri, 28 Feb 2025 03:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-54173</strong></p>
  <p>IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD reveals potentially sensitive information in trace files that could be read by a local user when webconsole trace is enabled.</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-1323</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-54173">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-27256 – IBM MQ Container 3.0.0, 3.0.1, 3.1.0 through 3.1.3 CD, 2.0.0 LTS through 2.0.22 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-27256</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-27256</guid>
    <pubDate>Mon, 27 Jan 2025 17:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-27256</strong></p>
  <p>IBM MQ Container 3.0.0, 3.0.1, 3.1.0 through 3.1.3 CD, 2.0.0 LTS through 2.0.22 LTS and 2.4.0 through 2.4.8, 2.3.0 through 2.3.3, 2.2.0 through 2.2.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27256">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-52898 – IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a local user...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52898</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52898</guid>
    <pubDate>Tue, 14 Jan 2025 17:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-52898</strong></p>
  <p>IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a local user to obtain sensitive information when a detailed technical error message is returned.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-209</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52898">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-52897 – IBM MQ 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a r...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52897</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52897</guid>
    <pubDate>Thu, 19 Dec 2024 18:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-52897</strong></p>
  <p>IBM MQ 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-209</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52897">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-51471 – IBM MQ Appliance 9.3 LTS, 9.3 CD, and 9.4 LTS web console could allow an authent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51471</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51471</guid>
    <pubDate>Thu, 19 Dec 2024 18:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-51471</strong></p>
  <p>IBM MQ Appliance 9.3 LTS, 9.3 CD, and 9.4 LTS web console could allow an authenticated user to cause a denial-of-service when trace is enabled due to information being written into memory outside of the intended buffer size.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51471">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-52896 – IBM MQ 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a r...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52896</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52896</guid>
    <pubDate>Thu, 19 Dec 2024 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-52896</strong></p>
  <p>IBM MQ 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-209</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52896">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-51470 – IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, 9.4 CD, IBM MQ Appliance 9.3 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51470</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51470</guid>
    <pubDate>Wed, 18 Dec 2024 20:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-51470</strong></p>
  <p>IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, 9.4 CD, IBM MQ Appliance 9.3 LTS, 9.3 CD, 9.4 LTS, and IBM MQ for HPE NonStop 8.1.0 through 8.1.0.25 could allow an authenticated user to cause a denial-of-service due to messages with improperly set values.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51470">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-40681 – IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow an aut...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-40681</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-40681</guid>
    <pubDate>Sat, 07 Sep 2024 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-40681</strong></p>
  <p>IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow an authenticated user in a specifically defined role, to bypass security restrictions and execute actions against the queue manager.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-40681">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-40680 – IBM MQ 9.3 CD and 9.4 LTS/CD could allow a local user to cause a denial of servi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-40680</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-40680</guid>
    <pubDate>Sat, 07 Sep 2024 14:15:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-40680</strong></p>
  <p>IBM MQ 9.3 CD and 9.4 LTS/CD could allow a local user to cause a denial of service due to improper memory allocation causing a segmentation fault.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-40680">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-39743 – IBM MQ Operator 3.2.2 and IBM MQ Operator 2.0.24 IBM MQ Container Developer Edit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-39743</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-39743</guid>
    <pubDate>Mon, 08 Jul 2024 14:15:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-39743</strong></p>
  <p>IBM MQ Operator 3.2.2 and IBM MQ Operator 2.0.24 IBM MQ Container Developer Edition is vulnerable to denial of service caused by incorrect memory de-allocation.   A remote attacker could exploit this vulnerability to cause the server to consume memory resources.  IBM X-Force ID:  297172.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-405</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39743">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-39742 – IBM MQ Operator 3.2.2 and IBM MQ Operator 2.0.24 could allow a user to bypass au...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-39742</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-39742</guid>
    <pubDate>Mon, 08 Jul 2024 14:15:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-39742</strong></p>
  <p>IBM MQ Operator 3.2.2 and IBM MQ Operator 2.0.24 could allow a user to bypass authentication under certain configurations due to a partial string comparison vulnerability.  IBM X-Force ID:  297169.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-187</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39742">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-35156 – IBM MQ 9.3 LTS and 9.3 CD could allow a remote attacker to obtain sensitive info...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35156</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35156</guid>
    <pubDate>Fri, 28 Jun 2024 19:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-35156</strong></p>
  <p>IBM MQ 9.3 LTS and 9.3 CD could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser.  This information could be used in further attacks against the system.  IBM X-Force ID:  292766.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-209</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35156">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-35116 – IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS, and 9.3 CD is vulnerable to a denial ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35116</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35116</guid>
    <pubDate>Fri, 28 Jun 2024 19:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-35116</strong></p>
  <p>IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS, and 9.3 CD is vulnerable to a denial of service attack caused by an error applying configuration changes.  IBM X-Force ID:  290335.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35116">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-35155 – IBM MQ Console 9.3 LTS and 9.3 CD could disclose could allow a remote attacker t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35155</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35155</guid>
    <pubDate>Fri, 28 Jun 2024 18:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-35155</strong></p>
  <p>IBM MQ Console 9.3 LTS and 9.3 CD could disclose could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser.  This information could be used in further attacks against the system.  IBM X-Force ID:  292765.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-209</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35155">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-31919 – IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS and 9.3 CD, in certain configurations,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-31919</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-31919</guid>
    <pubDate>Fri, 28 Jun 2024 18:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-31919</strong></p>
  <p>IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS and 9.3 CD, in certain configurations, is vulnerable to a denial of service attack caused by an error processing messages when an API Exit using MQBUFMH is used.  IBM X-Force ID:  290259.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-31919">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-31912 – IBM MQ 9.3 LTS and 9.3 CD could allow an authenticated user to escalate their pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-31912</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-31912</guid>
    <pubDate>Fri, 28 Jun 2024 18:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-31912</strong></p>
  <p>IBM MQ 9.3 LTS and 9.3 CD could allow an authenticated user to escalate their privileges under certain configurations due to incorrect privilege assignment.  IBM X-Force ID:  289894.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-31912">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-25015 – IBM MQ 9.2 LTS, 9.3 LTS, and 9.3 CD Internet Pass-Thru could allow a remote user...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-25015</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-25015</guid>
    <pubDate>Wed, 01 May 2024 17:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-25015</strong></p>
  <p>IBM MQ 9.2 LTS, 9.3 LTS, and 9.3 CD Internet Pass-Thru could allow a remote user to cause a denial of service by sending HTTP requests that would consume all available resources.  IBM X-Force ID:  281278.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-406</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-25015">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-25048 – IBM MQ Appliance 9.3 CD and LTS are vulnerable to a heap-based buffer overflow, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-25048</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-25048</guid>
    <pubDate>Sat, 27 Apr 2024 12:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-25048</strong></p>
  <p>IBM MQ Appliance 9.3 CD and LTS are vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote authenticated attacker could overflow a buffer and execute arbitrary code on the system or cause the server to crash.  IBM X-Force ID:  283137.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-25048">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-45177 – IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS and 9.3 CD is vulnerable to a denial-o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-45177</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-45177</guid>
    <pubDate>Wed, 20 Mar 2024 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-45177</strong></p>
  <p>IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS and 9.3 CD is vulnerable to a denial-of-service attack due to an error within the MQ clustering logic.  IBM X-Force ID:  268066.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45177">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-27255 – IBM MQ Operator 2.0.0 LTS, 2.0.18 LTS, 3.0.0 CD, 3.0.1 CD, 2.4.0 through 2.4.7, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-27255</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-27255</guid>
    <pubDate>Sun, 03 Mar 2024 12:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-27255</strong></p>
  <p>IBM MQ Operator 2.0.0 LTS, 2.0.18 LTS, 3.0.0 CD, 3.0.1 CD, 2.4.0 through 2.4.7, 2.3.0 through 2.3.3, 2.2.0 through 2.2.2, and 2.3.0 through 2.3.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.  IBM X-Force ID:  283905.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27255">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-47745 – IBM MQ Operator 2.0.0 LTS, 2.0.18 LTS, 3.0.0 CD, 3.0.1 CD, 2.4.0 through 2.4.7, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-47745</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-47745</guid>
    <pubDate>Sun, 03 Mar 2024 12:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-47745</strong></p>
  <p>IBM MQ Operator 2.0.0 LTS, 2.0.18 LTS, 3.0.0 CD, 3.0.1 CD, 2.4.0 through 2.4.7, 2.3.0 through 2.3.3, 2.2.0 through 2.2.2, and 2.3.0 through 2.3.3 stores or transmits user credentials in plain clear text which can be read by a local user using a trace command.  IBM X-Force ID:  272638.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-319</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-47745">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-25016 – IBM MQ and IBM MQ Appliance 9.0, 9.1, 9.2, 9.3 LTS and 9.3 CD could allow a remo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-25016</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-25016</guid>
    <pubDate>Sun, 03 Mar 2024 04:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-25016</strong></p>
  <p>IBM MQ and IBM MQ Appliance 9.0, 9.1, 9.2, 9.3 LTS and 9.3 CD could allow a remote unauthenticated attacker to cause a denial of service due to incorrect buffering logic.  IBM X-Force ID:  281279.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-25016">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-46177 – IBM MQ Appliance 9.3 LTS and 9.3 CD could allow a remote attacker to traverse di...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46177</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46177</guid>
    <pubDate>Mon, 18 Dec 2023 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-46177</strong></p>
  <p>IBM MQ Appliance 9.3 LTS and 9.3 CD could allow a remote attacker to traverse directories on the system.  An attacker could send a specially crafted URL request to view arbitrary files on the system.  IBM X-Force ID:  269536.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46177">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-46176 – IBM MQ Appliance 9.3 CD could allow a local attacker to gain elevated privileges...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46176</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46176</guid>
    <pubDate>Fri, 03 Nov 2023 01:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-46176</strong></p>
  <p>IBM MQ Appliance 9.3 CD could allow a local attacker to gain elevated privileges on the system, caused by improper validation of security keys.  IBM X-Force ID:  269535.</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-424</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46176">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-28513 – IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.2 CD, and 9.3 CD and IBM MQ Applian...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-28513</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-28513</guid>
    <pubDate>Wed, 19 Jul 2023 02:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-28513</strong></p>
  <p>IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.2 CD, and 9.3 CD and IBM MQ Appliance 9.2 LTS, 9.3 LTS, 9.2 CD, and 9.2 LTS, under certain configurations, is vulnerable to a denial of service attack caused by an error processing messages.  IBM X-Force ID:  250397.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-28513">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-28950 – IBM MQ 8.0, 9.0, 9.1, 9.2, and 9.3 could disclose sensitive user information fro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-28950</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-28950</guid>
    <pubDate>Fri, 19 May 2023 16:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-28950</strong></p>
  <p>IBM MQ 8.0, 9.0, 9.1, 9.2, and 9.3 could disclose sensitive user information from a trace file if that functionality has been enabled.  IBM X-Force ID:  251358.</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-28950">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-28514 – IBM MQ 8.0, 9.0, and 9.1 could allow a local user to obtain sensitive credential...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-28514</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-28514</guid>
    <pubDate>Fri, 19 May 2023 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-28514</strong></p>
  <p>IBM MQ 8.0, 9.0, and 9.1 could allow a local user to obtain sensitive credential information when a detailed technical error message is returned in a stack trace.  IBM X-Force ID:  250398.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-209</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-28514">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-26285 – IBM MQ 9.2 CD, 9.2 LTS, 9.3 CD, and 9.3 LTS could allow a remote attacker to cau...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-26285</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-26285</guid>
    <pubDate>Fri, 05 May 2023 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-26285</strong></p>
  <p>IBM MQ 9.2 CD, 9.2 LTS, 9.3 CD, and 9.3 LTS could allow a remote attacker to cause a denial of service due to an error processing invalid data.  IBM X-Force ID:  248418.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26285">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-22874 – IBM MQ Clients 9.2 CD, 9.3 CD, and 9.3 LTS are vulnerable to a denial of service...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22874</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22874</guid>
    <pubDate>Fri, 05 May 2023 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-22874</strong></p>
  <p>IBM MQ Clients 9.2 CD, 9.3 CD, and 9.3 LTS are vulnerable to a denial of service attack when processing configuration files.  IBM X-Force ID:  244216.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22874">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-43919 – IBM MQ 9.2 CD, 9.2 LTS, 9.3 CD, and 9.3 LTS could allow an authenticated attacke...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-43919</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-43919</guid>
    <pubDate>Fri, 05 May 2023 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-43919</strong></p>
  <p>IBM MQ 9.2 CD, 9.2 LTS, 9.3 CD, and 9.3 LTS could allow an authenticated attacker with authorization to craft messages to cause a denial of service.  IBM X-Force ID:  241354.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-43919">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-26284 – IBM MQ Certified Container 9.3.0.1 through 9.3.0.3 and 9.3.1.0 through 9.3.1.1 c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-26284</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-26284</guid>
    <pubDate>Wed, 15 Mar 2023 18:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-26284</strong></p>
  <p>IBM MQ Certified Container 9.3.0.1 through 9.3.0.3 and 9.3.1.0 through 9.3.1.1 could allow authenticated users with the cluster to be granted administration access to the MQ console due to improper access controls.  IBM X-Force ID:  248417.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26284">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-43902 – IBM MQ 9.2 CD, 9.2 LTS, 9.3 CD, and 9.3 LTS is vulnerable to a denial of service...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-43902</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-43902</guid>
    <pubDate>Fri, 10 Mar 2023 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-43902</strong></p>
  <p>IBM MQ 9.2 CD, 9.2 LTS, 9.3 CD, and 9.3 LTS is vulnerable to a denial of service attack caused by specially crafted PCF or MQSC messages.  IBM X-Force ID:  240832.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-43902">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-40237 – IBM MQ for HPE NonStop 8.1.0 is vulnerable to a denial of service attack due to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-40237</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-40237</guid>
    <pubDate>Mon, 27 Feb 2023 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-40237</strong></p>
  <p>IBM MQ for HPE NonStop 8.1.0 is vulnerable to a denial of service attack due to an error within the CCDT and channel synchronization logic.  IBM X-Force ID:  235727.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-40237">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-42436 – IBM MQ 8.0.0, 9.0.0, 9.1.0, 9.2.0, 9.3.0 Managed File Transfer could allow a loc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-42436</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-42436</guid>
    <pubDate>Sun, 12 Feb 2023 04:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-42436</strong></p>
  <p>IBM MQ 8.0.0, 9.0.0, 9.1.0, 9.2.0, 9.3.0 Managed File Transfer could allow a local user to obtain sensitive information from diagnostic files.  IBM X-Force ID:  238206.</p>
  <p><strong>CVSS:</strong> 4.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-42436">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-35719 – IBM MQ Internet Pass-Thru 2.1, 9.2 LTS and 9.2 CD stores potentially sensitive i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-35719</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-35719</guid>
    <pubDate>Mon, 14 Nov 2022 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-35719</strong></p>
  <p>IBM MQ Internet Pass-Thru 2.1, 9.2 LTS and 9.2 CD stores potentially sensitive information in trace files that could be read by a local user.</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-35719">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-31772 – IBM MQ 8.0, 9.0 LTS, 9.1 CD, 9.1 LTS, 9.2 CD, and 9.2 LTS could allow an authent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31772</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31772</guid>
    <pubDate>Fri, 11 Nov 2022 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-31772</strong></p>
  <p>IBM MQ 8.0, 9.0 LTS, 9.1 CD, 9.1 LTS, 9.2 CD, and 9.2 LTS could allow an authenticated and authorized user to cause a denial of service to the MQTT channels. IBM X-Force ID: 228335.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31772">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-40230 – "IBM MQ Appliance 9.2 CD, 9.2 LTS, 9.3 CD, and LTS 9.3 does not invalidate sessi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-40230</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-40230</guid>
    <pubDate>Thu, 03 Nov 2022 20:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-40230</strong></p>
  <p>"IBM MQ Appliance 9.2 CD, 9.2 LTS, 9.3 CD, and LTS 9.3 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 235532."</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-40230">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-22489 – IBM MQ 8.0, (9.0, 9.1, 9.2 LTS), and (9.1 and 9.2 CD) are vulnerable to an XML E...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-22489</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-22489</guid>
    <pubDate>Fri, 19 Aug 2022 19:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-22489</strong></p>
  <p>IBM MQ 8.0, (9.0, 9.1, 9.2 LTS), and (9.1 and 9.2 CD) are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 226339.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22489">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-22325 – IBM MQ (IBM MQ for HPE NonStop 8.1.0) can inadvertently disclose sensitive infor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-22325</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-22325</guid>
    <pubDate>Fri, 13 May 2022 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-22325</strong></p>
  <p>IBM MQ (IBM MQ for HPE NonStop 8.1.0) can inadvertently disclose sensitive information under certain circumstances to a local user from a stack trace. IBM X-Force ID: 218853.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22325">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-22356 – IBM MQ Appliance 9.2 CD and 9.2 LTS could allow an attacker to enumerate account...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-22356</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-22356</guid>
    <pubDate>Tue, 05 Apr 2022 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-22356</strong></p>
  <p>IBM MQ Appliance 9.2 CD and 9.2 LTS could allow an attacker to enumerate account credentials due to an observable discrepancy in valid and invalid login attempts. IBM X-Force ID: 220487.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-203</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22356">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-22355 – IBM MQ Appliance 9.2 CD and 9.2 LTS are vulnerable to a denial of service in the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-22355</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-22355</guid>
    <pubDate>Tue, 05 Apr 2022 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-22355</strong></p>
  <p>IBM MQ Appliance 9.2 CD and 9.2 LTS are vulnerable to a denial of service in the Login component of the application which could allow an attacker to cause a drop in performance.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22355">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-22316 – IBM MQ Appliance 9.2 CD and 9.2 LTS could allow an authenticated and authorized ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-22316</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-22316</guid>
    <pubDate>Wed, 23 Mar 2022 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-22316</strong></p>
  <p>IBM MQ Appliance 9.2 CD and 9.2 LTS could allow an authenticated and authorized user to cause a denial of service due to incorrectly configured authorization checks. IBM X-Force ID: 218276.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22316">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-22321 – IBM MQ Appliance 9.2 CD and 9.2 LTS local messaging users stored with a password...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-22321</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-22321</guid>
    <pubDate>Tue, 01 Mar 2022 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-22321</strong></p>
  <p>IBM MQ Appliance 9.2 CD and 9.2 LTS local messaging users stored with a password hash that provides insufficient protection. IBM X-Force ID: 218368.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-326</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22321">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-38986 – IBM MQ Appliance 9.2 CD and 9.2 LTS does not invalidate session after logout whi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38986</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38986</guid>
    <pubDate>Tue, 01 Mar 2022 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-38986</strong></p>
  <p>IBM MQ Appliance 9.2 CD and 9.2 LTS does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 212942.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38986">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-39034 – IBM MQ 9.1 LTS is vulnerable to a denial of service attack caused by an issue wi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-39034</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-39034</guid>
    <pubDate>Thu, 17 Feb 2022 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-39034</strong></p>
  <p>IBM MQ 9.1 LTS is vulnerable to a denial of service attack caused by an issue within the channel process. IBM X-Force ID: 213964.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39034">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-38950 – IBM MQ on HPE NonStop 8.0.4 and 8.1.0 is vulnerable to a privilege escalation at...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38950</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38950</guid>
    <pubDate>Tue, 14 Dec 2021 17:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-38950</strong></p>
  <p>IBM MQ on HPE NonStop 8.0.4 and 8.1.0 is vulnerable to a privilege escalation attack when SharedBindingsUserId is set to effective. IBM X-ForceID: 211404.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38950">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-39000 – IBM MQ Appliance 9.2 CD and 9.2 LTS could allow a local attacker to obtain sensi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-39000</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-39000</guid>
    <pubDate>Tue, 30 Nov 2021 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-39000</strong></p>
  <p>IBM MQ Appliance 9.2 CD and 9.2 LTS could allow a local attacker to obtain sensitive information by inclusion of sensitive data within diagnostics. IBM X-Force ID: 213215.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39000">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-38999 – IBM MQ Appliance could allow a local attacker to obtain sensitive information by...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38999</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38999</guid>
    <pubDate>Tue, 30 Nov 2021 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-38999</strong></p>
  <p>IBM MQ Appliance could allow a local attacker to obtain sensitive information by inclusion of sensitive data within trace.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38999">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-38967 – IBM MQ Appliance 9.2 CD and 9.2 LTS could allow a local privileged user to injec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38967</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38967</guid>
    <pubDate>Tue, 30 Nov 2021 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-38967</strong></p>
  <p>IBM MQ Appliance 9.2 CD and 9.2 LTS could allow a local privileged user to inject and execute malicious code. IBM X-Force ID: 212441.</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38967">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-38958 – IBM MQ Appliance 9.2 CD and 9.2 LTS is affected by a denial of service attack ca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38958</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38958</guid>
    <pubDate>Tue, 30 Nov 2021 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-38958</strong></p>
  <p>IBM MQ Appliance 9.2 CD and 9.2 LTS is affected by a denial of service attack caused by a concurrency issue. IBM X-Force ID: 212042</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38958">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-38875 – IBM MQ 8.0, 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.1 CD, and 9.2 CD is vulnerable to a den...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38875</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38875</guid>
    <pubDate>Tue, 23 Nov 2021 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-38875</strong></p>
  <p>IBM MQ 8.0, 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.1 CD, and 9.2 CD is vulnerable to a denial of service attack caused by an error processing messages. IBM X-Force ID: 208398.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38875">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-38949 – IBM MQ 7.5, 8.0, 9.0 LTS, 9.1 CD, and 9.1 LTS stores user credentials in plain c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38949</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38949</guid>
    <pubDate>Tue, 16 Nov 2021 17:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-38949</strong></p>
  <p>IBM MQ 7.5, 8.0, 9.0 LTS, 9.1 CD, and 9.1 LTS stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 211403.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38949">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-29843 – IBM MQ 9.1 LTS, 9.1 CD, 9.2 LTS, and 9.2CD is vulnerable to a denial of service ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29843</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29843</guid>
    <pubDate>Mon, 08 Nov 2021 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-29843</strong></p>
  <p>IBM MQ 9.1 LTS, 9.1 CD, 9.2 LTS, and 9.2CD is vulnerable to a denial of service attack caused by an issue processing message properties. IBM X-Force ID: 205203.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29843">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-4938 – IBM MQ Appliance 9.1 and 9.2 is vulnerable to cross-site request forgery which c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4938</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4938</guid>
    <pubDate>Mon, 12 Jul 2021 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-4938</strong></p>
  <p>IBM MQ Appliance 9.1 and 9.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 191815.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4938">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-4931 – IBM MQ 9.1 LTS, 9.2 LTS, and 9.1 CD AMQP Channels could allow an authenticated u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4931</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4931</guid>
    <pubDate>Wed, 24 Feb 2021 18:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-4931</strong></p>
  <p>IBM MQ 9.1 LTS, 9.2 LTS, and 9.1 CD AMQP Channels could allow an authenticated user to cause a denial of service due to an issue processing messages. IBM X-Force ID: 191747.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4931">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-4682 – IBM MQ 7.5, 8.0, 9.0, 9.1, 9.2 LTS, and 9.2 CD could allow a remote attacker to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4682</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4682</guid>
    <pubDate>Thu, 28 Jan 2021 13:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-4682</strong></p>
  <p>IBM MQ 7.5, 8.0, 9.0, 9.1, 9.2 LTS, and 9.2 CD could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization of trusted data. An attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 186509.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4682">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-4766 – IBM MQ Internet Pass-Thru 2.1 and 9.2 could allow a remote user to cause a denia...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4766</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4766</guid>
    <pubDate>Fri, 22 Jan 2021 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-4766</strong></p>
  <p>IBM MQ Internet Pass-Thru 2.1 and 9.2 could allow a remote user to cause a denial of service by sending malformed MQ data requests which would consume all available resources. IBM X-Force ID: 188093.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4766">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-4869 – IBM MQ Appliance 9.2 CD and 9.2 LTS is vulnerable to a denial of service, caused...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4869</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4869</guid>
    <pubDate>Mon, 11 Jan 2021 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-4869</strong></p>
  <p>IBM MQ Appliance 9.2 CD and 9.2 LTS is vulnerable to a denial of service, caused by a buffer overflow. A remote attacker could send a specially crafted SNMP query to cause the appliance to reload. IBM X-Force ID: 190831.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4869">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-4870 – IBM MQ 9.2 CD and LTS are vulnerable to a denial of service attack caused by an ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4870</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4870</guid>
    <pubDate>Mon, 21 Dec 2020 18:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-4870</strong></p>
  <p>IBM MQ 9.2 CD and LTS are vulnerable to a denial of service attack caused by an error processing connecting applications. IBM X-Force ID: 190833.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4870">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-4592 – IBM MQ Appliance 9.1.CD and LTS could allow an authenticated user, under nondefa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4592</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4592</guid>
    <pubDate>Wed, 18 Nov 2020 18:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-4592</strong></p>
  <p>IBM MQ Appliance 9.1.CD and LTS could allow an authenticated user, under nondefault configuration to cause a data corruption attack due to an error when using segmented messages.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4592">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-4528 – IBM MQ Appliance (IBM DataPower Gateway 10.0.0.0 and 2018.4.1.0 through 2018.4.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4528</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4528</guid>
    <pubDate>Tue, 06 Oct 2020 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-4528</strong></p>
  <p>IBM MQ Appliance (IBM DataPower Gateway 10.0.0.0 and 2018.4.1.0 through 2018.4.1.12) could allow a local user, under special conditions, to obtain highly sensitive information from log files. IBM X-Force ID: 182658.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4528">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-4465 – IBM MQ, IBM MQ Appliance, and IBM MQ for HPE NonStop 8.0, 9.1 CD, and 9.1 LTS is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4465</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4465</guid>
    <pubDate>Tue, 28 Jul 2020 12:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-4465</strong></p>
  <p>IBM MQ, IBM MQ Appliance, and IBM MQ for HPE NonStop 8.0, 9.1 CD, and 9.1 LTS is vulnerable to a buffer overflow vulnerability due to an error within the channel processing code. A remote attacker could overflow the buffer using an older client and cause a denial of service. IBM X-Force ID: 181562.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4465">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-4375 – IBM MQ, IBM MQ Appliance, IBM MQ for HPE NonStop 8.0, 9.1 CD, and 9.1 LTS could ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4375</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4375</guid>
    <pubDate>Tue, 28 Jul 2020 12:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-4375</strong></p>
  <p>IBM MQ, IBM MQ Appliance, IBM MQ for HPE NonStop 8.0, 9.1 CD, and 9.1 LTS could allow an attacker to cause a denial of service due to a memory leak caused by an error creating a dynamic queue. IBM X-Force ID: 179080.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4375">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-4319 – IBM MQ, IBM MQ Appliance, and IBM MQ for HPE NonStop 8.0, 9.1 LTS, and 9.1 CD co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4319</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4319</guid>
    <pubDate>Tue, 28 Jul 2020 12:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-4319</strong></p>
  <p>IBM MQ, IBM MQ Appliance, and IBM MQ for HPE NonStop 8.0, 9.1 LTS, and 9.1 CD could allow under special circumstances, an authenticated user to obtain sensitive information due to a data leak from an error message within the pre-v7 pubsub logic. IBM X-Force ID: 177402.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-209</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4319">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-4731 – IBM MQ Appliance 9.1.4.CD could allow a local attacker to obtain highly sensitiv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-4731</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-4731</guid>
    <pubDate>Tue, 28 Jul 2020 12:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-4731</strong></p>
  <p>IBM MQ Appliance 9.1.4.CD could allow a local attacker to obtain highly sensitive information by inclusion of sensitive data within trace. IBM X-Force ID: 172616.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-4731">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-4498 – IBM MQ Appliance 9.1 LTS and 9.1 CD could allow a local privileged user to obtai...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4498</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4498</guid>
    <pubDate>Mon, 27 Jul 2020 14:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-4498</strong></p>
  <p>IBM MQ Appliance 9.1 LTS and 9.1 CD could allow a local privileged user to obtain highly sensitve information due to inclusion of data within trace files. IBM X-Force ID: 182118.</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4498">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-4466 – IBM MQ for HPE NonStop 8.0.4 and 8.1.0 could allow a remote authenticated attack...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4466</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4466</guid>
    <pubDate>Mon, 20 Jul 2020 14:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-4466</strong></p>
  <p>IBM MQ for HPE NonStop 8.0.4 and 8.1.0 could allow a remote authenticated attacker could cause a denial of service due to an error within the Queue processing function. IBM X-Force ID: 181563.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4466">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-4376 – IBM MQ, IBM MQ Appliance, IBM MQ for HPE NonStop 8.0.4 and 8.1.0 could allow an ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4376</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4376</guid>
    <pubDate>Wed, 01 Jul 2020 15:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-4376</strong></p>
  <p>IBM MQ, IBM MQ Appliance, IBM MQ for HPE NonStop 8.0.4 and 8.1.0 could allow an attacker to cause a denial of service caused by an error within the pubsub logic. IBM X-Force ID: 179081.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4376">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-4320 – IBM MQ Appliance and IBM MQ AMQP Channels 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD do n...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4320</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4320</guid>
    <pubDate>Tue, 16 Jun 2020 14:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-4320</strong></p>
  <p>IBM MQ Appliance and IBM MQ AMQP Channels 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD do not correctly block or allow clients based on the certificate distinguished name SSLPEER setting. IBM X-Force ID: 177403.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4320">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-4310 – IBM MQ and MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 C are vulnerabl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4310</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4310</guid>
    <pubDate>Tue, 16 Jun 2020 14:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-4310</strong></p>
  <p>IBM MQ and MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 C are vulnerable to a denial of service attack due to an error within the Data Conversion logic. IBM X-Force ID: 177081.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4310">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-4352 – IBM MQ on HPE NonStop 8.0.4 and 8.1.0 is vulnerable to a privilege escalation at...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4352</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4352</guid>
    <pubDate>Fri, 29 May 2020 13:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-4352</strong></p>
  <p>IBM MQ on HPE NonStop 8.0.4 and 8.1.0 is vulnerable to a privilege escalation attack when running in restricted mode. IBM X-Force ID: 178427.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4352">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-4267 – IBM MQ and MQ Appliance 8.0, 9.1 LTS, and 9.1 CD could allow an authenticated us...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4267</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4267</guid>
    <pubDate>Fri, 24 Apr 2020 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-4267</strong></p>
  <p>IBM MQ and MQ Appliance 8.0, 9.1 LTS, and 9.1 CD could allow an authenticated user cause a denial of service due to a memory leak. IBM X-Force ID: 175840.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4267">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-4338 – IBM MQ 9.1.4 could allow a local attacker to obtain sensitive information by inc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4338</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4338</guid>
    <pubDate>Thu, 16 Apr 2020 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-4338</strong></p>
  <p>IBM MQ 9.1.4 could allow a local attacker to obtain sensitive information by inclusion of sensitive data within runmqras data. IBM X-Force ID: 177937.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4338">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-4762 – IBM MQ 9.0 and 9.1 is vulnerable to a denial of service attack due to an error i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-4762</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-4762</guid>
    <pubDate>Thu, 16 Apr 2020 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-4762</strong></p>
  <p>IBM MQ 9.0 and 9.1 is vulnerable to a denial of service attack due to an error in the Channel processing function. IBM X-Force ID: 173625.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-4762">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-4719 – IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD could al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-4719</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-4719</guid>
    <pubDate>Mon, 16 Mar 2020 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-4719</strong></p>
  <p>IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD could allow a local attacker to obtain sensitive information by inclusion of sensitive data within runmqras data.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-4719">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-4656 – IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD is vulne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-4656</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-4656</guid>
    <pubDate>Mon, 16 Mar 2020 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-4656</strong></p>
  <p>IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD is vulnerable to a denial of service attack that would allow an authenticated user to crash the queue and require a restart due to an error processing error messages. IBM X-Force ID: 170967.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-4656">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-4619 – IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD could al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-4619</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-4619</guid>
    <pubDate>Mon, 16 Mar 2020 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-4619</strong></p>
  <p>IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD could allow a local attacker to obtain sensitive information by inclusion of sensitive data within trace. IBM X-Force ID: 168862.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-209</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-4619">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-4620 – IBM MQ Appliance 8.0 and 9.0 LTS could allow a local attacker to bypass security...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-4620</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-4620</guid>
    <pubDate>Tue, 28 Jan 2020 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-4620</strong></p>
  <p>IBM MQ Appliance 8.0 and 9.0 LTS could allow a local attacker to bypass security restrictions caused by improper validation of environment variables. IBM X-Force ID: 168863.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-4620">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-4614 – IBM MQ and IBM MQ Appliance 8.0 and 9.0 LTS client connecting to a Queue Manager...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-4614</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-4614</guid>
    <pubDate>Tue, 28 Jan 2020 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-4614</strong></p>
  <p>IBM MQ and IBM MQ Appliance 8.0 and 9.0 LTS client connecting to a Queue Manager could cause a SIGSEGV denial of service caused by converting an invalid message. IBM X-Force ID: 168639.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-4614">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-4568 – IBM MQ and IBM MQ Appliance 8.0 and 9.0 LTS could allow a remote attacker with i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-4568</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-4568</guid>
    <pubDate>Tue, 28 Jan 2020 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-4568</strong></p>
  <p>IBM MQ and IBM MQ Appliance 8.0 and 9.0 LTS could allow a remote attacker with intimate knowledge of the server to cause a denial of service when receiving data on the channel. IBM X-Force ID: 166629.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-4568">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-4655 – IBM MQ 9.1.0.0, 9.1.0.1, 9.1.0.2, 9.1.0.3, 9.1.1, 9.1.2, and 9.1.3 is vulnerable...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-4655</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-4655</guid>
    <pubDate>Mon, 30 Dec 2019 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-4655</strong></p>
  <p>IBM MQ 9.1.0.0, 9.1.0.1, 9.1.0.2, 9.1.0.3, 9.1.1, 9.1.2, and 9.1.3 is vulnerable to a denial of service attack that would allow an authenticated user to reset client connections due to an error within the Data Conversion routine. IBM X-Force ID: 170966.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-4655">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-4560 – IBM MQ and IBM MQ Appliance 9.1 CD, 9.1 LTS, 9.0 LTS, and 8.0 is vulnerable to a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-4560</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-4560</guid>
    <pubDate>Mon, 16 Dec 2019 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-4560</strong></p>
  <p>IBM MQ and IBM MQ Appliance 9.1 CD, 9.1 LTS, 9.0 LTS, and 8.0 is vulnerable to a denial of service attack caused by channels processing poorly formatted messages. IBM X-Force ID: 166357.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-4560">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-4227 – IBM MQ 8.0.0.4 - 8.0.0.12, 9.0.0.0 - 9.0.0.6, 9.1.0.0 - 9.1.0.2, and 9.1.0 - 9.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-4227</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-4227</guid>
    <pubDate>Fri, 04 Oct 2019 14:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-4227</strong></p>
  <p>IBM MQ 8.0.0.4 - 8.0.0.12, 9.0.0.0 - 9.0.0.6, 9.1.0.0 - 9.1.0.2, and 9.1.0 - 9.1.2 AMQP Listeners could allow an unauthorized user to conduct a session fixation attack due to clients not being disconnected as they should. IBM X-Force ID: 159352.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-384</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-4227">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-4141 – IBM MQ 7.1.0.0 - 7.1.0.9, 7.5.0.0 - 7.5.0.9, 8.0.0.0 - 8.0.0.11, 9.0.0.0 - 9.0.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-4141</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-4141</guid>
    <pubDate>Fri, 27 Sep 2019 14:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-4141</strong></p>
  <p>IBM MQ 7.1.0.0 - 7.1.0.9, 7.5.0.0 - 7.5.0.9, 8.0.0.0 - 8.0.0.11, 9.0.0.0 - 9.0.0.6, 9.1.0.0 - 9.1.0.2, and 9.1.1 - 9.1.2 is vulnerable to a denial of service attack caused by a memory leak in the clustering code. IBM X-Force ID: 158337.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-4141">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
