Impact
IBM MQ can allow a remote attacker to execute arbitrary code by exploiting unsafe JNDI lookup processing when the IVT application is deployed. The flaw permits unauthenticated attackers to run code on the host, compromising confidentiality, integrity, and availability with no user interaction. The weakness is a form of input manipulation (CWE-74).
Affected Systems
The affected products are IBM MQ versions 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 LTS, and 10.0.0.0. IBM recommends applying the 9.3.0.42 cumulative security update to all 9.3 LTS installations, the 9.4.0.26 update to all 9.4 LTS installations, and upgrading 9.3 CD, 9.4 CD, and 10.0.0.0 installations to IBM MQ 10.0.0.5.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity. The EPSS score of <1% suggests a low probability of exploitation, but the lack of authentication required and the potential impact justify immediate remediation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated remote JNDI injection that can be triggered by a malicious client connecting to the MQ server.
OpenCVE Enrichment