Impact
IBM MQ Appliance suffers from a heap buffer overflow that occurs during processing of protocol messages before authentication is completed. The flaw can be exploited by sending a crafted message that triggers the overflow, which may result in a denial of service or, in the worst case, the execution of arbitrary code on the appliance. This weakness is identified as CWE-122. The urgent nature of the flaw stems from its ability to compromise confidentiality, integrity, and availability of the messaging system. The likely attack vector is an unauthenticated remote attacker targeting the appliance’s messaging ports with a malformed protocol message. Based on the description, it is inferred that the attacker does not need to gain prior authentication to trigger the vulnerability.
Affected Systems
The vulnerability affects all IBM MQ Appliance releases that were listed in the CNA solution. For the 9.4 LTS stream, every build from 9.4.0.0 onward is impacted, and the fix is supplied in fix pack 9.4.0.26 or later firmware. In the 9.4 CD stream, the M2003 revision requires an upgrade to 10.0.0.5 or newer firmware, while the M2002 revision can be mitigated by applying the cumulative security update 9.4.5.3 or later firmware. All 10 LTS releases are affected and a fix pack 10.0.0.5 or newer is required.
Risk and Exploitability
With a CVSS score of 10, this flaw represents the maximum severity. The EPSS score of < 1% indicates a low but nonzero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, but that does not diminish its seriousness. Attackers who can reach the appliance’s messaging ports may trigger the heap overflow by sending a malicious message before authentication, potentially causing a denial of service or executing code with privileged rights on the appliance. Immediate patching is strongly advised to mitigate this critical risk.
OpenCVE Enrichment