Impact
The vulnerability arises from improper validation of deeply nested certificate data during TLS certificate processing in IBM MQ. A remote attacker who presents a trusted client certificate can trigger a denial of service and may cause memory contents to be affected. The impact is service interruption and potential unintended memory state changes, which could disrupt queue manager operations.
Affected Systems
Affected versions include IBM MQ 9.1 LTS releases from 9.1.0.0 through 9.1.0.37, IBM MQ 9.2 LTS releases from 9.2.0.0 through 9.2.0.43, IBM MQ 9.3 LTS releases from 9.3.0.0 through 9.3.0.41 and CD releases through 9.3.5.1, IBM MQ 9.4 LTS releases from 9.4.0.0 through 9.4.0.25 and CD releases through 9.4.5.1, and IBM MQ 10.0.0.0. The vendor advisory lists cumulative security updates that address each of these releases.
Risk and Exploitability
The CVSS score of 7 denotes high severity. Although the EPSS score is below 1 %, indicating a low but non‑zero probability of exploitation, no public exploits are listed and the vulnerability is not catalogued in CISA KEV. The requirement for a trusted TLS client certificate means that environments that allow unauthenticated or external client certificates are at higher risk. Successful exploitation results in service denial and possible memory corruption, which could affect availability but not necessarily facilitate further attacks unless additional vulnerabilities exist.
OpenCVE Enrichment