Impact
The flaw in IBM MQ for HPE NonStop stems from improper validation of message distribution list structures, permitting an authenticated attacker to send crafted messages that can crash the system or, in some cases, execute arbitrary code. This corresponds to a heap-based buffer exploitation weakness.
Affected Systems
IBM MQ for HPE NonStop 8.1.0.40 and any earlier 8.1.0 releases are affected. The product is deployed on the HPE NonStop platform. IBM advises installing CSU 8.1.0.41 to remediate the issue.
Risk and Exploitability
The vulnerability has a CVSS score of 8.8, indicating high severity, with an EPSS score of 0.0059 and not listed in the CISA KEV catalog. An attacker must have authenticated access and the ability to target distribution lists, suggesting a need for privileged accounts, but the potential for denial of service or remote code execution warrants rapid mitigation.
OpenCVE Enrichment