PatchSiren cyber security CVE debrief
CVE-2016-0360 IBM CVE debrief
CVE-2016-0360 is a critical deserialization vulnerability in IBM WebSphere MQ JMS client versions 7.0.1, 7.1, 7.5, 8.0, and 9.0. IBM and NVD describe client classes that deserialize objects from untrusted sources, which could allow arbitrary Java code execution when vulnerable classes are present on the classpath.
- Vendor
- IBM
- Product
- Websphere Mq Jms
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-15
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-15
- Advisory updated
- 2026-05-13
Who should care
Java application owners, JVM platform teams, and security teams running IBM WebSphere MQ JMS client libraries—especially where the application handles untrusted input or uses broad classpaths.
Technical summary
NVD classifies the issue as CWE-502 (deserialization of untrusted data) and assigns CVSS v3.0 9.8 with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The affected IBM WebSphere MQ JMS client versions listed in the official record are 7.0.1, 7.1, 7.5, 8.0, and 9.0.
Defensive priority
Critical. The combination of unauthenticated network reachability, no user interaction, and high confidentiality/integrity/availability impact makes this a high-priority patching and exposure-reduction item.
Recommended defensive actions
- Inventory all applications and servers using IBM WebSphere MQ JMS client versions 7.0.1, 7.1, 7.5, 8.0, or 9.0.
- Apply IBM PSIRT remediation guidance from the vendor advisory and move to a remediated IBM-supported release.
- Reduce or eliminate deserialization of untrusted objects in affected application paths.
- Review Java classpaths for unnecessary or vulnerable classes and remove any that expand the attack surface.
- Limit exposure of affected client code to untrusted sources until remediation is complete.
Evidence notes
The official NVD record lists the affected IBM WebSphere MQ JMS client versions and classifies the weakness as CWE-502 with CVSS v3.0 9.8. The IBM vendor advisory referenced in NVD is the primary remediation source. The supplied corpus does not include exact fixed-version details, so the debrief avoids naming a specific patched release.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-0360 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-0360
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-0360 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-0360
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.