Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY30 SECURITY RECORDS

IBM

MQ Appliance

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2026-10747 18 Sep 2026 MQ Appliance: 9.4 LTS ≤ 9.4.0.0 to 9.4.0.25, 9.4 CD ≤ 9.4.1.0 to 9.4.5.2, 10.0.0.0 ≤ 10.0.0.1 only This vulnerability is addressed under APAR DT472411; IBM strongly recommends addressing the vulnerability now.; IBM MQ Appliance version 9.4 LTS; Apply IBM MQ Appliance fix pack 9.4.0.26 https://www.ibm.com/support/fixcentral/swg/selectFixes , or later firmware.; IBM MQ Appliance version 9.4 CD - M2003; Upgrade to IBM MQ Appliance 10.0.0.5 https://www.ibm.com/support/fixcentral/swg/selectFixes , or later firmware.; IBM MQ Appliance version 9.4 CD - M2002; Apply IBM MQ Appliance cumulative security update 9.4.5.3 https://www.ibm.com/support/fixcentral/swg/selectFixes , or later firmware.; IBM MQ Appliance version 10 LTS; Apply IBM MQ Appliance fix pack 10.0.0.5 https://www.ibm.com/support/fixcentral/swg/selectFixes , or later firmware. Update reference ↗
CVE-2025-14456 3 Mar 2026 9.4 CD ≤ 9.4.4.0 to 9.4.4.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-51471 19 Dec 2024 9.3 LTS, 9.3 CD, 9.4 LTS No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-25048 27 Apr 2024 9.3 LTS, 9.3 CD No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2023-46177 18 Dec 2023 9.3 LTS, 9.3 CD An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2023-46176 3 Nov 2023 9.3 CD An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2022-22356 5 Apr 2022 9.2 LTS; 9.2 CD An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2022-22355 5 Apr 2022 9.2 LTS; 9.2 CD An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2022-22316 23 Mar 2022 9.2 LTS; 9.2 CD An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2022-22321 1 Mar 2022 9.2 LTS; 9.2 CD An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2021-38986 1 Mar 2022 9.2 LTS; 9.2 CD An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2021-39000 30 Nov 2021 9.2.0.0; 9.2.1; 9.2.0.1; 9.2.2; 9.2.0.2; 9.2.0.3; 9.2.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2021-38999 30 Nov 2021 9.2.0.0; 9.2.1; 9.2.0.1; 9.2.2; 9.2.0.2; 9.2.0.3; 9.2.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2021-38967 30 Nov 2021 9.2.0.0; 9.2.1; 9.2.0.1; 9.2.2; 9.2.0.2; 9.2.0.3; 9.2.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2021-38958 30 Nov 2021 9.2.0.0; 9.2.1; 9.2.0.1; 9.2.2; 9.2.0.2; 9.2.0.3; 9.2.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2021-29843 8 Nov 2021 9.1.LTS; 9.1.CD; 9.2.LTS; 9.2.CD No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2020-4938 12 Jul 2021 9.1; 9.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2020-4931 24 Feb 2021 9.1.0.0; 9.1.0.1; 9.1.1; 9.1.0.2; 9.1.2; 9.1.0.3; 9.1.3; 9.1.0.4 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2020-4869 11 Jan 2021 9.2.0.0; 9.2.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2020-4592 18 Nov 2020 9.1.LTS; 9.1.CD An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2020-4465 28 Jul 2020 8.0; 9.1.LTS; 9.1.CD An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2020-4375 28 Jul 2020 8.0; 9.1.LTS; 9.1.CD An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2020-4319 28 Jul 2020 8.0; 9.1.LTS; 9.1.CD An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2019-4731 28 Jul 2020 9.1.4.CD An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2020-4498 27 Jul 2020 9.1.0.0; 9.1.0.1; 9.1.1; 9.1.0.2; 9.1.2; 9.1.0.3; 9.1.3; 9.1.0.4 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2020-4267 24 Apr 2020 8.0.0.3; 8.0.0.4; 8.0.0.5; 8.0.0.6; 8.0.0.0; 8.0.0.8; 8.0.0.10; 8.0.0.11 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2019-4620 28 Jan 2020 8.0.0.3; 8.0.0.4; 8.0.0.5; 8.0.0.6; 8.0.0.0; 8.0.0.10; 8.0.0.11; 9.1.0.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2019-4294 20 Aug 2019 8.0.0.3; 8.0.0.4; 8.0.0.5; 8.0.0.6; 8.0.0.0; 8.0.0.8; 8.0.0.10; 9.1.0.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2018-1429 23 Mar 2018 9.0.1; 9.0.2; 9.0.3; 9.0.4 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2017-1318 18 Jul 2017 8.0; 8.0.0.3; 8.0.0.4; 8.0.0.5; 9.0.1; 9.0.2; 8.0.0.6 No fixed version is explicitly recorded in the structured CVE data. Use CVE record

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.