Impact
The IBM MQ Console mistakenly allows any authenticated non‑administrative user to create and start queue managers because authorization checks are not enforced. This flaw enables a user without administrative privileges to elevate their role within the messaging system, potentially modifying queue configurations, redirecting traffic, and compromising the integrity and availability of the MQ environment.
Affected Systems
IBM MQ deployments that include releases 9.3 LTS, 9.4 LTS, the 9.3 and 9.4 community development builds, and the 10.0.0.0 version are impacted. The vulnerability is resolved by applying cumulative security updates 9.3.0.42 and 9.4.0.26 for the LTS releases and upgrading to IBM MQ 10.0.0.5 for the CD builds and 10.0.0.0.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate‑to‑high risk. The EPSS score of less than 1% suggests a low but non‑zero likelihood of exploitation, and the flaw is not listed in the CISA KEV catalog. Because an attacker must be an authenticated non‑administrative user with console access, the attack vector is limited to environments where such users are granted visibility of the console; once logged in, the system permits creation and startup of queue managers, effectively elevating the attacker’s privileges.
OpenCVE Enrichment