Impact
IBM MQ’s XA transaction handling contains a stack buffer overflow (CWE-122) that is triggered when an authenticated attacker submits a specially crafted XA transaction identifier. The overflow corrupts control data, which can allow execution of arbitrary code with the privileges of the MQ process or, if exploitation fails, can cause a denial of service by crashing the queue manager.
Affected Systems
Vulnerable instances include IBM MQ 9.1 LTS versions up to 9.1.0.37, 9.2 LTS up to 9.2.0.43, 9.3 LTS up to 9.3.5.1 and 9.4 LTS up to 9.4.5.1, as well as the 9.3 CD, 9.4 CD and the 10.0.0.0 build. All affected versions are patchable by applying the cumulative security updates listed in the vendor’s advisory (9.1.0.38 for 9.1, 9.2.0.44 for 9.2, 9.3.0.42 for 9.3, 9.4.0.26 for 9.4, or upgrading to 10.0.0.5 for the CD and 10.0.0.0 builds).
Risk and Exploitability
The CVSS score of 8.8 classifies the vulnerability as high severity. The EPSS score of <1% indicates a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, but the remote code execution potential combined with the requirement for authenticated access means that the threat is significant. An attacker who can authenticate to the queue manager from a remote network can potentially compromise the host or disrupt service until a patch or mitigation is applied.
OpenCVE Enrichment