Show filters
391 Total Results
Displaying 101-110 of 391
Sort by:
Attacker Value
Unknown
CVE-2021-3763
Disclosure Date: August 23, 2022 (last updated February 24, 2025)
A flaw was found in the Red Hat AMQ Broker management console in version 7.8 where an existing user is able to access some limited information even when the role the user is assigned to should not be allow access to the management console. The main impact is to confidentiality as this flaw means some role bindings are incorrectly checked, some privileged meta information such as queue names and configuration details are disclosed but the impact is limited as not all information is accessible and there is no affect to integrity.
0
Attacker Value
Unknown
CVE-2022-35278
Disclosure Date: August 23, 2022 (last updated February 24, 2025)
In Apache ActiveMQ Artemis prior to 2.24.0, an attacker could show malicious content and/or redirect users to a malicious URL in the web console by using HTML in the name of an address or queue.
0
Attacker Value
Unknown
CVE-2022-22489
Disclosure Date: August 18, 2022 (last updated February 24, 2025)
IBM MQ 8.0, (9.0, 9.1, 9.2 LTS), and (9.1 and 9.2 CD) are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 226339.
0
Attacker Value
Unknown
CVE-2020-14379
Disclosure Date: August 16, 2022 (last updated February 24, 2025)
A flaw was found in Red Hat AMQ Broker in a way that a XEE attack can be done via Broker's configuration files, leading to denial of service and information disclosure.
0
Attacker Value
Unknown
CVE-2022-22326
Disclosure Date: July 29, 2022 (last updated February 24, 2025)
IBM Datapower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.5, and 2018.4.1.0 through 2018.4.1.18 could allow unauthorized viewing of logs and files due to insufficient authorization checks. IBM X-Force ID: 218856.
0
Attacker Value
Unknown
CVE-2022-1833
Disclosure Date: June 21, 2022 (last updated February 23, 2025)
A flaw was found in AMQ Broker Operator 7.9.4 installed via UI using OperatorHub where a low-privilege user that has access to the namespace where the AMQ Operator is deployed has access to clusterwide edit rights by checking the secrets. The service account used for building the Operator gives more permission than expected and an attacker could benefit from it. This requires at least an already compromised low-privilege account or insider attack.
0
Attacker Value
Unknown
CVE-2022-22325
Disclosure Date: May 12, 2022 (last updated October 07, 2023)
IBM MQ (IBM MQ for HPE NonStop 8.1.0) can inadvertently disclose sensitive information under certain circumstances to a local user from a stack trace. IBM X-Force ID: 218853.
0
Attacker Value
Unknown
CVE-2021-22680
Disclosure Date: May 03, 2022 (last updated February 23, 2025)
NXP MQX Versions 5.1 and prior are vulnerable to integer overflow in mem_alloc, _lwmem_alloc and _partition functions. This unverified memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution.
0
Attacker Value
Unknown
CVE-2022-22356
Disclosure Date: April 04, 2022 (last updated February 23, 2025)
IBM MQ Appliance 9.2 CD and 9.2 LTS could allow an attacker to enumerate account credentials due to an observable discrepancy in valid and invalid login attempts. IBM X-Force ID: 220487.
0
Attacker Value
Unknown
CVE-2022-22355
Disclosure Date: April 04, 2022 (last updated October 07, 2023)
IBM MQ Appliance 9.2 CD and 9.2 LTS are vulnerable to a denial of service in the Login component of the application which could allow an attacker to cause a drop in performance.
0