Impact
IBM MQ is vulnerable to an authenticated attacker with cluster access being able to send a malformed command message that exceeds the accepted size limits. The flaw can trigger a denial of service or, in certain configurations, arbitrary code execution. The weakness is classified as CWE‑470, indicating that user‑supplied input is improperly evaluated as code.
Affected Systems
The issue affects IBM MQ LTS and CD releases. Specifically versions 9.1 up to 9.1.0.37, 9.2 up to 9.2.0.43, 9.3 up to 9.3.5.1, 9.4 up to 9.4.5.1, and the 9.3 CD, 9.4 CD, and 10.0.0.0 releases. The advisory lists these affected builds.
Risk and Exploitability
The CVSS score of 7.5 reflects medium‑to‑high severity. EPSS indicates a very low exploitation probability (<1 %). The vulnerability is not listed in the CISA KEV catalog, so there is no confirmed large‑scale public exploitation. Nonetheless, any environment that allows authenticated cluster traffic from untrusted sources could be at risk of system disruption or code execution if the flaw is exploited. Prompt remediation is strongly recommended for exposed or cloud‑based MQ deployments.
OpenCVE Enrichment