Impact
The vulnerability allows a remote actor to send crafted AMS policy data responses that are not properly validated by the IBM MQ C client, leading to an out‑of‑bounds memory access (CWE‑122). The fault can trigger a service crash, causing a denial of service, or, in worst cases, permit arbitrary code execution on the affected system.
Affected Systems
Affected systems are IBM MQ for HPE NonStop versions 8.1.0 through 8.1.0.40, including the 8.1.0.40IT49921 release. The issue originates in the C client that communicates with queue managers, and all installations of this product family that have not applied the 8.1.0.41 customer support update are vulnerable. The documented fix is a patch to update to CSU 8.1.0.41.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, and the EPSS score is not available, which means no quantified probability of exploitation is currently supplied. The vulnerability is not listed in the CISA KEV catalog, but because it can be triggered remotely via AMS policy queries, a risk of service interruption or compromise exists. In practice, an attacker would need network access to the MQ queue manager endpoint and could exploit the flaw by sending a malformed AMS policy request that causes mis‑calculated buffer lengths during validation.
OpenCVE Enrichment