Vulnerabilities > IBM > Websphere MQ

DATE CVE VULNERABILITY TITLE RISK
2014-10-19 CVE-2014-4822 Credentials Management vulnerability in IBM Websphere MQ and Websphere MQ Explorer
IBM WebSphere MQ classes for Java libraries 8.0 before 8.0.0.1 and Websphere MQ Explorer 7.5 before 7.5.0.5 and 8.0 before 8.0.0.2 allow local users to discover preconfigured cleartext passwords via an unspecified trace operation.
local
ibm CWE-255
1.9
2014-10-02 CVE-2014-4793 Permissions, Privileges, and Access Controls vulnerability in IBM Websphere MQ 8.0.0.0
IBM WebSphere MQ 8.x before 8.0.0.1 does not properly enforce CHLAUTH rules for blocking client connections in certain circumstances related to the CONNAUTH attribute, which allows remote authenticated users to bypass intended queue-manager access restrictions via unspecified vectors.
network
low complexity
ibm CWE-264
6.5
2014-05-07 CVE-2014-0911 Unspecified vulnerability in IBM Websphere MQ
inetd in IBM WebSphere MQ 7.1.x before 7.1.0.5 and 7.5.x before 7.5.0.4 allows remote attackers to cause a denial of service (disk or CPU consumption) via unspecified vectors.
network
ibm
4.3
2014-03-02 CVE-2013-4054 Path Traversal vulnerability in IBM Websphere MQ 7.5/7.5.0.1/7.5.0.2
Directory traversal vulnerability in WMQ Telemetry in IBM WebSphere MQ 7.5 before 7.5.0.3 allows remote attackers to read arbitrary files via a crafted URI.
network
ibm CWE-22
4.3
2013-07-02 CVE-2013-3028 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IBM Websphere MQ
Multiple buffer overflows in mqm programs in IBM WebSphere MQ 7.0.x before 7.0.1.11, 7.1.x before 7.1.0.3, and 7.5.x before 7.5.0.2 on non-Windows platforms allow local users to gain privileges via unspecified vectors.
local
low complexity
ibm CWE-119
4.6
2012-09-25 CVE-2012-2199 Resource Management Errors vulnerability in IBM Websphere MQ
The server message channel agent in the queue manager in the server in IBM WebSphere MQ 7.0.1 before 7.0.1.9, 7.1, and 7.5 on Solaris allows remote attackers to cause a denial of service (invalid address alignment exception and daemon crash) via vectors involving a multiplexed channel.
network
low complexity
ibm oracle CWE-399
5.0
2012-08-29 CVE-2012-3295 Permissions, Privileges, and Access Controls vulnerability in IBM Websphere MQ 7.1
IBM WebSphere MQ 7.1, when an SVRCONN channel is used, allows remote attackers to bypass the security-configuration setup step and obtain queue-manager access via unspecified vectors.
network
ibm CWE-264
4.3
2012-08-17 CVE-2012-3294 Cross-Site Request Forgery (CSRF) vulnerability in IBM Websphere MQ and Websphere MQ Managed File Transfer
Multiple cross-site request forgery (CSRF) vulnerabilities in the Web Gateway component in IBM WebSphere MQ File Transfer Edition 7.0.4 and earlier, and WebSphere MQ - Managed File Transfer 7.5, allow remote attackers to hijack the authentication of arbitrary users for requests that (1) add user accounts via the /wmqfteconsole/Filespaces URI, (2) modify permissions via the /wmqfteconsole/FileSpacePermisssions URI, or (3) add MQ Message Descriptor (MQMD) user accounts via the /wmqfteconsole/UploadUsers URI.
network
ibm CWE-352
6.8
2012-08-17 CVE-2012-2206 Permissions, Privileges, and Access Controls vulnerability in IBM Websphere MQ
The Web Gateway component in IBM WebSphere MQ File Transfer Edition 7.0.4 and earlier allows remote authenticated users to read files of arbitrary users via vectors involving a username in a URI, as demonstrated by a modified metadata=fteSamplesUser field to the /transfer URI.
network
ibm CWE-264
3.5
2011-11-26 CVE-2011-1378 Permissions, Privileges, and Access Controls vulnerability in IBM Websphere MQ 6.0
IBM WebSphere MQ 6.0 on OpenVMS, when the default rights of the MQM group are established, does not properly verify User Authorization File (UAF) data, which allows local users to kill listener processes and the command server via a control command.
local
ibm hp CWE-264
1.9