CVE-2016-6089
- EPSS 0.04%
- Published 07.06.2017 17:29:00
- Last modified 20.04.2025 01:37:25
IBM WebSphere MQ 9.0.0.1 and 9.0.2 could allow a local user to write to a file or delete files in a directory they should not have access to due to improper access controls. IBM X-Force ID: 117926.
CVE-2017-1145
- EPSS 0.5%
- Published 20.03.2017 16:59:01
- Last modified 20.04.2025 01:37:25
IBM WebSphere MQ 8.0.0.6 does not properly terminate channel agents when they are no longer needed, which could allow a user to cause a denial of service through resource exhaustion. IBM Reference #: 1999672.
CVE-2016-8971
- EPSS 0.41%
- Published 07.03.2017 17:59:00
- Last modified 20.04.2025 01:37:25
IBM WebSphere MQ 8.0 could allow an authenticated user with queue manager permissions to cause a segmentation fault which would result in the box having to be rebooted to resume normal operations. IBM Reference #: 1998663.
- EPSS 0.34%
- Published 24.02.2017 18:59:00
- Last modified 20.04.2025 01:37:25
IBM WebSphere MQ 8.0 could allow an authenticated user with authority to create a cluster object to cause a denial of service to MQ clustering. IBM Reference #: 1998647.
CVE-2016-8986
- EPSS 0.2%
- Published 22.02.2017 19:59:00
- Last modified 20.04.2025 01:37:25
IBM WebSphere MQ 8.0 could allow an authenticated user with access to the queue manager to bring down MQ channels using specially crafted HTTP requests. IBM Reference #: 1998648.
CVE-2016-8915
- EPSS 0.28%
- Published 22.02.2017 19:59:00
- Last modified 20.04.2025 01:37:25
IBM WebSphere MQ 8.0 could allow an authenticated user with access to the queue manager and queue, to deny service to other channels running under the same process. IBM Reference #: 1998649.
CVE-2016-3052
- EPSS 0.21%
- Published 22.02.2017 19:59:00
- Last modified 20.04.2025 01:37:25
Under non-standard configurations, IBM WebSphere MQ might send password data in clear text over the network. This data could be intercepted using man in the middle techniques.
CVE-2016-3013
- EPSS 0.53%
- Published 22.02.2017 19:59:00
- Last modified 20.04.2025 01:37:25
IBM WebSphere MQ 8.0 could allow an authenticated user to crash the MQ channel due to improper data conversion handling. IBM Reference #: 1998661.
CVE-2016-0379
- EPSS 0.32%
- Published 26.09.2016 04:59:02
- Last modified 12.04.2025 10:46:40
IBM WebSphere MQ 7.5 before 7.5.0.7 and 8.0 before 8.0.0.5 mishandles protocol flows, which allows remote authenticated users to cause a denial of service (channel outage) by leveraging queue-manager rights.
CVE-2016-0260
- EPSS 0.67%
- Published 29.06.2016 01:59:02
- Last modified 12.04.2025 10:46:40
Memory leak in queue-manager agents in IBM WebSphere MQ 8.x before 8.0.0.5 allows remote attackers to cause a denial of service (heap memory consumption) by triggering many errors.