Impact
An authenticated attacker can execute arbitrary code on client applications that use IBM MQ Java or JMS client libraries. The vulnerability arises from a deserialization filter bypass in exception handling, which allows malicious data to be processed without proper validation. This weakness is a classic example of CWE-502, deserialization of untrusted data.
Affected Systems
IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.4 LTS, and the CD releases of 9.3, 9.4, and 10.0.0.0 are vulnerable. Patches are available for each version: cumulative security update 9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26, and upgrading to IBM MQ 10.0.0.5 for the CD releases.
Risk and Exploitability
The CVSS score of 7.5 indicates a moderate to high severity vulnerability that can lead to full system compromise if exploited. The EPSS score is 0.5%, indicating a very low but nonzero probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, but the remote code execution potential and requirement for only authenticated access make it a significant risk for organizations that run IBM MQ client applications.
OpenCVE Enrichment