CVE-2025-36100
- EPSS 0.02%
- Published 07.09.2025 00:37:00
- Last modified 08.09.2025 16:25:38
IBM MQ LTS 9.1.0.0 through 9.1.0.29, 9.2.0.0 through 9.2.0.36, 9.3.0.0 through 9.3.0.30 and 9.4.0.0 through 9.4.0.12 and IBM MQ CD 9.3.0.0 through 9.3.5.1 and 9.4.0.0 through 9.4.3.0 Java and JMS stores a password in client configuration files when ...
CVE-2025-3631
- EPSS 0.05%
- Published 11.07.2025 18:37:38
- Last modified 23.07.2025 19:08:03
An IBM MQ 9.3 and 9.4 Client connecting to an MQ Queue Manager can cause a SIGSEGV in the AMQRMPPA channel process terminating it.
CVE-2025-0985
- EPSS 0.03%
- Published 28.02.2025 17:15:15
- Last modified 30.09.2025 15:26:28
IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD stores potentially sensitive information in environment variables that could be obtained by a local user.
CVE-2024-54175
- EPSS 0.03%
- Published 28.02.2025 17:15:15
- Last modified 26.09.2025 16:30:51
IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow a local user to cause a denial of service due to an improper check for unusual or exceptional conditions.
CVE-2025-23225
- EPSS 0.12%
- Published 28.02.2025 03:15:10
- Last modified 03.07.2025 20:25:35
IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow an authenticated user to cause a denial of service due to the improper handling of invalid headers sent to the queue.
CVE-2025-0975
- EPSS 0.24%
- Published 28.02.2025 03:15:10
- Last modified 03.07.2025 20:41:35
IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD console could allow an authenticated user to execute code due to improper neutralization of escape characters.
CVE-2024-54173
- EPSS 0.01%
- Published 28.02.2025 03:15:09
- Last modified 03.07.2025 20:44:08
IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD reveals potentially sensitive information in trace files that could be read by a local user when webconsole trace is enabled.
CVE-2024-52898
- EPSS 0.03%
- Published 14.01.2025 17:15:17
- Last modified 03.07.2025 20:10:10
IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a local user to obtain sensitive information when a detailed technical error message is returned.
CVE-2024-52897
- EPSS 0.03%
- Published 19.12.2024 18:15:23
- Last modified 19.08.2025 21:31:25
IBM MQ 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned.
CVE-2024-52896
- EPSS 0.03%
- Published 19.12.2024 17:15:09
- Last modified 19.08.2025 21:31:33
IBM MQ 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned.