Impact
IBM MQ’s distribution list processing contains an integer overflow that an authenticated attacker can exploit to cause a denial of service or, in certain conditions, execute arbitrary code. The flaw is classified as CWE-190, an integer overflow vulnerability that can corrupt memory boundaries and lead to privilege escalation or crash. As the attack requires valid credentials, the impact is limited to environments where the attacker can log in as a user with sufficient permissions to send messages to the vulnerable queue manager.
Affected Systems
Affected versions include IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.4 LTS, the 9.3 CD, 9.4 CD, and 10.0.0.0 releases. IBM supplies cumulative security updates for each unless a newer major version is installed: 9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26, and an upgrade to 10.0.0.5 for the CD and 10.0.0.0 series.
Risk and Exploitability
The CVSS score of 8.8 reflects the severity of potential code execution. The EPSS score is <1%, and the vulnerability is not listed in the CISA KEV catalog at this time. Exploitation can occur over the network from any host that can authenticate to the queue manager; it does not require physical access, and the flaw can be triggered by sending a crafted message or list to the distribution channel. Because the condition demands valid authentication, mitigations such as limiting user privileges or disabling unnecessary protocols can reduce risk, but the most effective defense is to apply the listed cumulative security updates.
OpenCVE Enrichment