IBM MQ and IBM MQ Appliance 9.0, 9.1, 9.2, 9.3 LTS and 9.3 CD could allow a remote unauthenticated attacker to cause a denial of service due to incorrect buffering logic. IBM X-Force ID: 281279.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HIBM Mq
APPIbm9.0.0.0 – 9.0.0.23 (excl.)9.1.0.0 – 9.1.0.20 (excl.)9.2.0 – 9.2.0.22 (excl.)9.3.0 – 9.3.0.16 (excl.)IBM Mq Appliance
APPIbm9.3.0.0 – 9.3.5.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth BypassDoS
Related vulnerabilities
CVE-2022-22489CRITICAL9.1PL ✓same product
IBM MQ — podatność XXE umożliwiająca ujawnienie danych i wyczerpanie zasobów
CVE-2020-4682CRITICAL9.8PL ✓same product
RCE poprzez niebezpieczną deserializację w IBM MQ
CVE-2025-36128HIGH7.5same product
IBM MQ 9.1, 9.2, 9.3, 9.4 LTS and 9.3, 9.4 CD is vulnerable to a denial of service, caused by improper enforce...
CVE-2025-0975HIGH8.8same product
IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD console could allow an authenticated user to execute code due to i...
CVE-2024-31912HIGH7.5same product
IBM MQ 9.3 LTS and 9.3 CD could allow an authenticated user to escalate their privileges under certain configu...