Impact
The vulnerability is caused by unsafe deserialization of client data that allows JNDI injection. An authenticated attacker who can influence the data sent to the IBM MQ Java client can trigger execution of arbitrary code on the client system. This is a classic deserialization flaw (CWE-502) that leads to remote code execution.
Affected Systems
Affected are IBM MQ 9.1 LTS versions 9.1.0.0 through 9.1.0.37; IBM MQ 9.2 LTS 9.2.0.0 through 9.2.0.43; IBM MQ 9.3 releases 9.3.0.0 through 9.3.5.1 (CD and LTS); IBM MQ 9.4 releases 9.4.0.0 through 9.4.5.1 (CD and LTS); and IBM MQ 10.0.0.0. All affected products require Java and use the MQ Java client libraries, so any environment where a client connects to an IBM MQ broker and is authenticated is potentially vulnerable.
Risk and Exploitability
The CVSS score is 8.5, indicating high severity. The EPSS score is less than 1%, but the lack of a KEV listing suggests the vulnerability is not yet known to be exploited, yet its high impact warrants prompt action. Exploitation requires an authenticated attacker who can send crafted data to the MQ Java client, typically via a malicious JMS or other message, enabling JNDI injection and arbitrary code execution on the client host.
OpenCVE Enrichment