Description
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of queue manager responses when requesting AMS policy data.
Published: 2026-09-18
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service and potential arbitrary code execution
Action: Apply Patch
AI Analysis

Impact

The vulnerability allows a remote actor to send crafted AMS policy data responses that are not properly validated by the IBM MQ C client, leading to an out‑of‑bounds memory access (CWE‑122). The fault can trigger a service crash, causing a denial of service, or, in worst cases, permit arbitrary code execution on the affected system.

Affected Systems

Affected systems are IBM MQ for HPE NonStop versions 8.1.0 through 8.1.0.40, including the 8.1.0.40IT49921 release. The issue originates in the C client that communicates with queue managers, and all installations of this product family that have not applied the 8.1.0.41 customer support update are vulnerable. The documented fix is a patch to update to CSU 8.1.0.41.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity, and the EPSS score is not available, which means no quantified probability of exploitation is currently supplied. The vulnerability is not listed in the CISA KEV catalog, but because it can be triggered remotely via AMS policy queries, a risk of service interruption or compromise exists. In practice, an attacker would need network access to the MQ queue manager endpoint and could exploit the flaw by sending a malformed AMS policy request that causes mis‑calculated buffer lengths during validation.

Generated by OpenCVE AI on September 19, 2026 at 10:46 UTC.

Remediation

Vendor Solution

IBM MQ V8.1 for HPE NonStop 8.1.0.40IT49921 Upgrade to CSU 8.1.0.41 https://www.ibm.com/support/fixcentral/swg/selectFixes IBM strongly recommends addressing this vulnerability now by installing CSU 8.1.0.41.


OpenCVE Recommended Actions

  • Apply the IBM MQ V8.1 for HPE NonStop customer support update CSU 8.1.0.41 immediately.
  • If the update cannot be applied right away, isolate the affected MQ instances from external networks and restrict access to the queue manager to trusted hosts only.
  • Monitor MQ logs for unusually terminated connections or errors related to AMS policy data, and investigate any suspected attempts to send malformed requests.

Generated by OpenCVE AI on September 19, 2026 at 10:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of queue manager responses when requesting AMS policy data.
Title IBM MQ for HPE NonStop is vulnerable to a denial of service issue
First Time appeared Ibm
Ibm mq For Hpe Nonstop
Weaknesses CWE-122
CPEs cpe:2.3:a:ibm:mq_for_hpe_nonstop:8.1.0.40:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq_for_hpe_nonstop:8.1.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm mq For Hpe Nonstop
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Mq For Hpe Nonstop
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-22T03:55:57.218Z

Reserved: 2026-06-09T02:26:46.975Z

Link: CVE-2026-11727

cve-icon Vulnrichment

Updated: 2026-09-19T14:08:11.796Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T20:17:04.050

Modified: 2026-09-22T19:32:25.730

Link: CVE-2026-11727

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:45:18Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow