IBM / Integration Bus
24 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-3602 | IBM App Connect Enterprise and IBM Integration Bus for z/OS toolkit is vulnerable to an sql injection | MEDIUM | 5.5 | Jun 30, 2026 |
| CVE-2025-36014 | IBM Integration Bus for z/OS code injection | HIGH | 8.2 | Jul 7, 2025 |
| CVE-2024-22356 | IBM App Connect Enterprise and IBM Integration Bus for z/OS information disclosure | MEDIUM | 4.9 | Mar 26, 2024 |
| CVE-2024-27265 | IBM Integration Bus for z/OS cross-site request forgery | MEDIUM | 6.5 | Mar 14, 2024 |
| CVE-2024-22332 | IBM Integration Bus for z/OS denial of service | MEDIUM | 6.5 | Feb 9, 2024 |
| CVE-2023-45176 | IBM App Connect Enterprise and IBM Integration Bus denial of service | MEDIUM | 6.2 | Oct 14, 2023 |
| CVE-2018-1801 | IBM App Connect V11.0.0.0 through V11.0.0.1, IBM Integration Bus V10.0.0.0 through V10.0.0.13, IBM Integration Bus V9.0.0.0 through V9.0.0.10, and WebSphere Me… | MEDIUM | 5.3 | Feb 4, 2019 |
| CVE-2017-1418 | IBM Integration Bus 9.0.0.0, 9.0.0.11, 10.0.0.0, and 10.0.0.14 (including IBM WebSphere Message Broker 8.0.0.0 and 8.0.0.9) has insecure permissions on certain… | MEDIUM | 5.5 | Nov 26, 2018 |
| CVE-2017-1693 | IBM Integration Bus 9.0 and 10.0 could allow an attacker that has captured a valid session id to hijack another users session during a small timeframe before t… | MEDIUM | 5.6 | Jan 19, 2018 |
| CVE-2017-1694 | IBM Integration Bus 9.0 and 10.0 transmits user credentials in plain in clear text which can be read by an attacker using man in the middle techniques. IBM X-F… | HIGH | 8.1 | Dec 20, 2017 |
| CVE-2017-1126 | IBM WebSphere Message Broker (IBM Integration Bus 9.0 and 10.0) could allow an unauthorized user to obtain sensitive information about software versions that c… | MEDIUM | 5.3 | Oct 3, 2017 |
| CVE-2017-1144 | IBM WebSphere Message Broker could allow a local user with specialized access to prevent the message broker from starting. IBM X-Force ID: 122033. | LOW | 2.5 | Jul 5, 2017 |
| CVE-2017-1207 | IBM WebSphere Message Broker stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 123777. | MEDIUM | 5.5 | Jul 5, 2017 |
| CVE-2016-9706 | IBM Integration Bus 9.0 and 10.0 and WebSphere Message Broker SOAP FLOWS is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE)… | CRITICAL | 9.1 | Feb 15, 2017 |
| CVE-2016-9010 | IBM WebSphere Message Broker 9.0 and 10.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a maliciou… | MEDIUM | 6.1 | Feb 15, 2017 |
| CVE-2016-8918 | IBM Integration Bus, under non default configurations, could allow a remote user to authenticate without providing valid credentials. | MEDIUM | 5.9 | Feb 1, 2017 |
| CVE-2016-0394 | IBM Integration Bus and WebSphere Message broker sets incorrect permissions for an object that could allow a local attacker to manipulate certain files. | LOW | 3.3 | Feb 1, 2017 |
| CVE-2016-2961 | The integration server in IBM Integration Bus 9 before 9.0.0.6 and 10 before 10.0.0.5 and WebSphere Message Broker 8 before 8.0.0.8 allows remote attackers to… | MEDIUM | 5.3 | Jul 2, 2016 |
| CVE-2015-7399 | IBM WebSphere Message Broker 7 before 7.0.0.8 and 8 before 8.0.0.6 and IBM Integration Bus 9 before 9.0.0.3 and 10 before 10.0.0.0 allow remote attackers to ob… | MEDIUM | 5.3 | Jan 11, 2016 |
| CVE-2015-5011 | IBM WebSphere Message Broker 8 before 8.0.0.6 and Integration Bus 9 before 9.0.0.4 do not check authorization for MQSISTARTMSGFLOW and MQSISTOPMSGFLOW commands… | LOW | 3.2 | Oct 26, 2015 |
| CVE-2015-2018 | IBM Integration Bus 9 and 10 before 10.0.0.1 and WebSphere Message Broker 7 before 7.0.0.8 and 8 before 8.0.0.7 do not ensure that the correct security profile… | LOW | 3.5 | Aug 23, 2015 |
| CVE-2015-0118 | IBM WebSphere Message Broker Toolkit 7 before 7007 IF2 and 8 before 8005 IF1 and Integration Toolkit 9 before 9003 IF1 are distributed with MQ client JAR files… | MEDIUM | 4.3 | Jun 28, 2015 |
| CVE-2014-6170 | The HTTPInput node in IBM WebSphere Message Broker 7.0 before 7.0.0.8 and 8.0 before 8.0.0.6 and IBM Integration Bus 9.0 before 9.0.0.4 allows remote attackers… | MEDIUM | 5.0 | Feb 2, 2015 |
| CVE-2014-4819 | The web user interface in IBM WebSphere Message Broker 8.0 before 8.0.0.6 and IBM Integration Bus 9.0 before 9.0.0.3 allows remote authenticated users to obtai… | MEDIUM | 4.0 | Sep 18, 2014 |
Showing 1 to 24 of 24 CVEs