CVE-2016-0360: IBM WebSphere Mq Jms
Critical severity, CVSS 9.8. EPSS: 2.8% chance of exploitation in the next 30 days.
IBM Websphere MQ JMS 7.0.1, 7.1, 7.5, 8.0, and 9.0 client provides classes that deserialize objects from untrusted sources which could allow a malicious user to execute arbitrary Java code by adding vulnerable classes to the classpath. IBM Reference #: 1983457.
Affected products
- IBM WebSphere Mq Jms: version 7.0.1 only; version 7.1 only; version 7.5 only; version 8.0 only; version 9.0 only
Published 2017-02-15. Last modified 2026-06-17.