Vulnerabilities > IBM > Websphere MQ > 5.3.1.14

DATE CVE VULNERABILITY TITLE RISK
2017-02-22 CVE-2016-3052 Information Exposure vulnerability in IBM Websphere MQ
Under non-standard configurations, IBM WebSphere MQ might send password data in clear text over the network.
network
ibm CWE-200
4.3
2017-02-22 CVE-2016-3013 Data Processing Errors vulnerability in IBM Websphere MQ
IBM WebSphere MQ 8.0 could allow an authenticated user to crash the MQ channel due to improper data conversion handling.
network
low complexity
ibm CWE-19
4.0
2015-04-27 CVE-2015-0176 Cross-site Scripting vulnerability in IBM Websphere MQ
Cross-site scripting (XSS) vulnerability in MQ XR WebSockets Listener in WMQ Telemetry in IBM WebSphere MQ 8.0 before 8.0.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URI that is included in an error response.
network
ibm CWE-79
4.3
2008-03-09 CVE-2007-6705 Permissions, Privileges, and Access Controls vulnerability in IBM Websphere MQ
The WebSphere MQ XA 5.3 before FP13 and 6.0.x before 6.0.2.1 client for Windows, when running in an MTS or a COM+ environment, grants the PROCESS_DUP_HANDLE privilege to the Everyone group upon connection to a queue manager, which allows local users to duplicate an arbitrary handle and possibly hijack an arbitrary process.
local
ibm CWE-264
3.3