- EPSS 0.17%
- Veröffentlicht 15.09.2026 17:14:57
- Zuletzt bearbeitet 17.09.2026 17:16:38
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow a remote attacker with a trusted TLS clien...
CVE-2026-12351
- EPSS 0.86%
- Veröffentlicht 15.09.2026 17:14:32
- Zuletzt bearbeitet 16.09.2026 19:21:55
IBM MQ 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 LTS, and 10.0.0.0 could allow a remote attacker to execute arbitrary code due to unsafe JNDI lookup processing when the IVT applica...
CVE-2026-12354
- EPSS 0.45%
- Veröffentlicht 15.09.2026 17:13:11
- Zuletzt bearbeitet 16.09.2026 19:21:55
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to execute arbit...
CVE-2026-12355
- EPSS 0.38%
- Veröffentlicht 15.09.2026 17:12:54
- Zuletzt bearbeitet 16.09.2026 19:21:55
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an attacker to perform JNDI injection atta...
CVE-2026-12666
- EPSS 0.26%
- Veröffentlicht 15.09.2026 17:08:05
- Zuletzt bearbeitet 17.09.2026 17:16:38
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 Classes for Java could allow an authenticated attacker...
CVE-2026-12667
- EPSS 0.36%
- Veröffentlicht 15.09.2026 17:07:31
- Zuletzt bearbeitet 16.09.2026 19:24:58
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to read files fr...
CVE-2026-12728
- EPSS 0.59%
- Veröffentlicht 15.09.2026 17:07:10
- Zuletzt bearbeitet 17.09.2026 15:16:40
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to execute arbit...
CVE-2026-13293
- EPSS 0.56%
- Veröffentlicht 14.09.2026 21:17:02
- Zuletzt bearbeitet 16.09.2026 19:21:55
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow a remote authenticated attacker to execute...
CVE-2026-13287
- EPSS 0.39%
- Veröffentlicht 14.09.2026 21:17:01
- Zuletzt bearbeitet 16.09.2026 19:24:58
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 is vulnerable to an XML external entity injection (XXE...
CVE-2026-13285
- EPSS 0.39%
- Veröffentlicht 14.09.2026 21:17:01
- Zuletzt bearbeitet 18.09.2026 20:17:05
IBM MQ is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.