CVEs (23)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.5 is vulnerable to code injection by a privileged user with access to the IIB install directory. |
1Ibm 2App Connect Enterprise Integration BusJan 28, 2025 Mar 26, 2024 N/A· v4 4.9 MEDIUM· v3 N/A· v2 IBM App Connect Enterprise 11.0.0.1 through 11.0.0.23, 12.0.1.0 through 12.0.9.0 and IBM Integration Bus for z/OS 10.1 through 10.1.0.2store potentially sensitive information in log or trace files that could be read by a...Show more |
IBM Integration Bus for z/OS 10.1 through 10.1.0.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts....Show more |
The IBM Integration Bus for z/OS 10.1 through 10.1.0.2 AdminAPI is vulnerable to a denial of service due to file system exhaustion. IBM X-Force ID: 279972. |
1Ibm 2App Connect Enterprise Integration BusNov 21, 2024 Oct 14, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 IBM App Connect Enterprise 11.0.0.1 through 11.0.0.23, 12.0.1.0 through 12.0.10.0 and IBM Integration Bus 10.1 through 10.1.0.1 are vulnerable to a denial of service for integration nodes on Windows. IBM X-Force ID: 24...Show more |
1Ibm 3App Connect Integration BusWebsphere Message BrokerNov 21, 2024 Feb 4, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 IBM App Connect V11.0.0.0 through V11.0.0.1, IBM Integration Bus V10.0.0.0 through V10.0.0.13, IBM Integration Bus V9.0.0.0 through V9.0.0.10, and WebSphere Message Broker V8.0.0.0 through V8.0.0.9 is vulnerable to a XML...Show more |
1Ibm 2Integration Bus Websphere Message BrokerNov 21, 2024 Nov 26, 2018 N/A· v4 5.5 MEDIUM· v3 3.6 LOW· v2 IBM Integration Bus 9.0.0.0, 9.0.0.11, 10.0.0.0, and 10.0.0.14 (including IBM WebSphere Message Broker 8.0.0.0 and 8.0.0.9) has insecure permissions on certain files. A local attacker could exploit this vulnerability to...Show more |
IBM Integration Bus 9.0 and 10.0 could allow an attacker that has captured a valid session id to hijack another users session during a small timeframe before the session times out. IBM X-Force ID: 134164. |
IBM Integration Bus 9.0 and 10.0 transmits user credentials in plain in clear text which can be read by an attacker using man in the middle techniques. IBM X-Force ID: 134165. |
1Ibm 2Integration Bus Websphere Message BrokerMay 13, 2026 Oct 4, 2017 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 IBM WebSphere Message Broker (IBM Integration Bus 9.0 and 10.0) could allow an unauthorized user to obtain sensitive information about software versions that could lead to further attacks. IBM X-Force ID: 121341. |
1Ibm 2Integration Bus Websphere Message BrokerMay 13, 2026 Jul 5, 2017 N/A· v4 2.5 LOW· v3 1.9 LOW· v2 IBM WebSphere Message Broker could allow a local user with specialized access to prevent the message broker from starting. IBM X-Force ID: 122033. |
1Ibm 2Integration Bus Websphere Message BrokerMay 13, 2026 Jul 5, 2017 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 IBM WebSphere Message Broker stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 123777. |
1Ibm 2Integration Bus Websphere Message BrokerMay 13, 2026 Feb 15, 2017 N/A· v4 9.1 CRITICAL· v3 8.5 HIGH· v2 IBM Integration Bus 9.0 and 10.0 and WebSphere Message Broker SOAP FLOWS is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could expl...Show more |
1Ibm 2Integration Bus Websphere Message BrokerMay 13, 2026 Feb 15, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 IBM WebSphere Message Broker 9.0 and 10.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerabilit...Show more |
IBM Integration Bus, under non default configurations, could allow a remote user to authenticate without providing valid credentials. |
1Ibm 2Integration Bus Websphere Message BrokerMay 13, 2026 Feb 1, 2017 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 IBM Integration Bus and WebSphere Message broker sets incorrect permissions for an object that could allow a local attacker to manipulate certain files. |
1Ibm 2Integration Bus Websphere Message BrokerMay 6, 2026 Jul 2, 2016 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The integration server in IBM Integration Bus 9 before 9.0.0.6 and 10 before 10.0.0.5 and WebSphere Message Broker 8 before 8.0.0.8 allows remote attackers to obtain sensitive Tomcat version information by sending a malf...Show more |
1Ibm 2Integration Bus Websphere Message BrokerMay 6, 2026 Jan 11, 2016 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 IBM WebSphere Message Broker 7 before 7.0.0.8 and 8 before 8.0.0.6 and IBM Integration Bus 9 before 9.0.0.3 and 10 before 10.0.0.0 allow remote attackers to obtain sensitive information about the HTTP server via unspecif...Show more |
1Ibm 2Integration Bus Websphere Message BrokerMay 6, 2026 Oct 26, 2015 N/A· v4 N/A· v3 3.2 LOW· v2 IBM WebSphere Message Broker 8 before 8.0.0.6 and Integration Bus 9 before 9.0.0.4 do not check authorization for MQSISTARTMSGFLOW and MQSISTOPMSGFLOW commands, which allows local users to bypass intended access restrict...Show more |
1Ibm 2Integration Bus Websphere Message BrokerMay 6, 2026 Aug 23, 2015 N/A· v4 N/A· v3 3.5 LOW· v2 IBM Integration Bus 9 and 10 before 10.0.0.1 and WebSphere Message Broker 7 before 7.0.0.8 and 8 before 8.0.0.7 do not ensure that the correct security profile is selected, which allows remote authenticated users to obta...Show more |