Show filters
391 Total Results
Displaying 181-190 of 391
Sort by:
Attacker Value
Unknown

CVE-2020-4320

Disclosure Date: June 15, 2020 (last updated February 21, 2025)
IBM MQ Appliance and IBM MQ AMQP Channels 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD do not correctly block or allow clients based on the certificate distinguished name SSLPEER setting. IBM X-Force ID: 177403.
Attacker Value
Unknown

CVE-2020-4310

Disclosure Date: June 12, 2020 (last updated November 28, 2024)
IBM MQ and MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 C are vulnerable to a denial of service attack due to an error within the Data Conversion logic. IBM X-Force ID: 177081.
Attacker Value
Unknown

CVE-2020-13849

Disclosure Date: June 04, 2020 (last updated February 21, 2025)
The MQTT protocol 3.1.1 requires a server to set a timeout value of 1.5 times the Keep-Alive value specified by a client, which allows remote attackers to cause a denial of service (loss of the ability to establish new connections), as demonstrated by SlowITe.
Attacker Value
Unknown

CVE-2020-4352

Disclosure Date: May 28, 2020 (last updated November 27, 2024)
IBM MQ on HPE NonStop 8.0.4 and 8.1.0 is vulnerable to a privilege escalation attack when running in restricted mode. IBM X-Force ID: 178427.
Attacker Value
Unknown

CVE-2020-1941

Disclosure Date: May 14, 2020 (last updated February 21, 2025)
In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in the view that lists the contents of a queue.
Attacker Value
Unknown

CVE-2019-17572

Disclosure Date: May 14, 2020 (last updated February 21, 2025)
In Apache RocketMQ 4.2.0 to 4.6.0, when the automatic topic creation in the broker is turned on by default, an evil topic like “../../../../topic2020” is sent from rocketmq-client to the broker, a topic folder will be created in the parent directory in brokers, which leads to a directory traversal vulnerability. Users of the affected versions should apply one of the following: Upgrade to Apache RocketMQ 4.6.1 or later.
Attacker Value
Unknown

CVE-2020-11016

Disclosure Date: April 30, 2020 (last updated February 21, 2025)
IntelMQ Manager from version 1.1.0 and before version 2.1.1 has a vulnerability where the backend incorrectly handled messages given by user-input in the "send" functionality of the Inspect-tool of the Monitor component. An attacker with access to the IntelMQ Manager could possibly use this issue to execute arbitrary code with the privileges of the webserver. Version 2.1.1 fixes the vulnerability.
Attacker Value
Unknown

CVE-2020-4267

Disclosure Date: April 22, 2020 (last updated February 21, 2025)
IBM MQ and MQ Appliance 8.0, 9.1 LTS, and 9.1 CD could allow an authenticated user cause a denial of service due to a memory leak. IBM X-Force ID: 175840.
Attacker Value
Unknown

CVE-2020-4338

Disclosure Date: April 15, 2020 (last updated February 21, 2025)
IBM MQ 9.1.4 could allow a local attacker to obtain sensitive information by inclusion of sensitive data within runmqras data. IBM X-Force ID: 177937.
Attacker Value
Unknown

CVE-2019-4762

Disclosure Date: April 15, 2020 (last updated November 27, 2024)
IBM MQ 9.0 and 9.1 is vulnerable to a denial of service attack due to an error in the Channel processing function. IBM X-Force ID: 173625.