Impact
The vulnerability is a buffer overflow caused by malformed compressed data processed on channels where compression is enabled. With a specially crafted packet, a remote attacker can trigger a denial of service or the execution of arbitrary code. This weakness is identified as CWE-787 and the resulting impact is remote code execution.
Affected Systems
IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.4 LTS, 9.3 CD, 9.4 CD, and 10.0.0.0 are affected. Each version requires update to the latest cumulative security release (v9.1.0.38, v9.2.0.44, v9.3.0.42, v9.4.0.26, or v10.0.0.5 for 10.0.0.0) to remediate the issue.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, and the EPSS score of less than 1% indicates a very low but non‑zero exploitation probability, yet it is not listed in the CISA KEV catalog. The likely attack vector is a remote attacker delivering malformed compressed data to a channel established over the network, which triggers the buffer overflow. The resulting impact can be a denial of service or arbitrary code execution that may compromise the MQ system and the services that depend on it.
OpenCVE Enrichment