Impact
An integer overflow in the MQINQ request handler allows an authenticated attacker to trigger a denial of service or, in worst‑case scenarios, execute arbitrary code on the queue manager. The flaw occurs when the service processes malformed queue name requests, leading to unchecked arithmetic that corrupts internal state or memory.
Affected Systems
IBM MQ versions 9.1 LTS, 9.2 LTS, 9.3 LTS, and 9.4 LTS, as well as the 9.3 and 9.4 CD releases and IBM MQ 10.0.0.0 are affected. All of these build lines are listed in the vendor certification database and are covered by the corresponding cumulative security updates.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS score is not available, which does not rule out exploitation but limits visibility into current threat activity. The flaw is not listed in the CISA KEV catalog. A likely attack path involves an authenticated user with access to the MQ network endpoint submitting a crafted INQ request; the need for authentication limits the visibility surface but does not eliminate risk.
OpenCVE Enrichment