📦 Mq Appliance

by Ibm

🔍 What is Mq Appliance?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2020-4682

CRITICAL CVSS 9.8 Jan 28, 2021

CVE-2020-4682 is a critical remote code execution vulnerability in IBM MQ caused by unsafe deserialization of trusted data. Attackers can exploit this to execute arbitrary code on affected systems. Th...

CVE-2025-0975

HIGH CVSS 8.8 Feb 28, 2025

CVE-2025-0975 is an improper input validation vulnerability in IBM MQ console that allows authenticated users to execute arbitrary code by exploiting escape character handling. This affects IBM MQ 9.3...

CVE-2024-25048

HIGH CVSS 7.5 Apr 27, 2024

IBM MQ Appliance 9.3 CD and LTS have a heap-based buffer overflow vulnerability due to improper bounds checking. Remote authenticated attackers can exploit this to execute arbitrary code or crash the ...

CVE-2024-25016

HIGH CVSS 7.5 Mar 3, 2024

This vulnerability in IBM MQ and IBM MQ Appliance allows a remote unauthenticated attacker to cause a denial of service due to incorrect buffering logic. It affects IBM MQ versions 9.0, 9.1, 9.2, 9.3 ...

CVE-2020-4938

HIGH CVSS 8.8 Jul 12, 2021

This CVE describes a cross-site request forgery (CSRF) vulnerability in IBM MQ Appliance versions 9.1 and 9.2. It allows attackers to trick authenticated users into performing unauthorized actions on ...

CVE-2025-3631

MEDIUM CVSS 6.5 Jul 11, 2025

A use-after-free vulnerability (CWE-416) in IBM MQ 9.3 and 9.4 allows a malicious client to crash the AMQRMPPA channel process via SIGSEGV when connecting to a queue manager. This affects IBM MQ queue...

CVE-2025-23225

MEDIUM CVSS 6.5 Feb 28, 2025

This vulnerability in IBM MQ allows authenticated users to send specially crafted messages with invalid headers to queues, causing the queue manager to crash and resulting in denial of service. It aff...

CVE-2024-54173

MEDIUM CVSS 4.7 Feb 28, 2025

IBM MQ versions 9.3 and 9.4 expose sensitive information in trace files when webconsole trace is enabled. This information disclosure vulnerability allows local users to read potentially sensitive dat...

CVE-2024-51471

MEDIUM CVSS 5.3 Dec 19, 2024

This vulnerability in IBM MQ Appliance web console allows authenticated users to cause denial-of-service when trace functionality is enabled. It occurs due to buffer overflow when writing information ...

CVE-2024-51470

MEDIUM CVSS 6.5 Dec 18, 2024

This vulnerability in IBM MQ allows authenticated users to cause denial-of-service by sending messages with improperly set values. It affects multiple IBM MQ versions across different platforms includ...