Impact
IBM MQ for HPE NonStop is affected by an integer overflow in the MQINQ request validation. The flaw allows an authenticated attacker to send crafted requests that overload internal counters, causing the message queue to crash and result in a denial of service. In addition, the overflow could potentially lead to unauthorized escalation of privileges on the affected system by corrupting internal state.
Affected Systems
The vulnerability impacts IBM MQ for HPE NonStop versions 8.1.0 through 8.1.0.40. The supported fix is the IBM MQ V8.1 for HPE NonStop 8.1.0.40IT49923 upgrade to CSU 8.1.0.41.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack requires authentication against the MQ server; therefore, the likely attack vector is an internal or remote authenticated user with privileges to issue MQINQ requests.
OpenCVE Enrichment