Impact
The vulnerability arises from improper validation of cluster migration data during queue manager startup, allowing an authenticated attacker to cause a denial of service or, in some cases, execute arbitrary code. This flaw is a Heap-based buffer overflow, which compromises the availability of the MQ service and could potentially affect data integrity and confidentiality if arbitrary code execution is achieved.
Affected Systems
IBM MQ for HPE NonStop versions 8.1.0 through 8.1.0.40 are affected. The vulnerability applies to the non-Stop edition of IBM MQ and impacts systems running any of those builds.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, but the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack requires authenticated access to the queue manager, so the threat is limited to insiders or compromised user accounts that can perform a cluster migration. Once exploited, the attacker can bring the messaging service offline or potentially run code on the host at startup, making the risk significant for critical messaging workloads.
OpenCVE Enrichment