Impact
IBM MQ can allow a remote attacker to execute arbitrary code by exploiting unsafe JNDI lookup processing when the IVT application is deployed. The flaw permits unauthenticated attackers to run code on the host, compromising confidentiality, integrity, and availability with no user interaction. The weakness is a form of input manipulation (CWE-74).
Affected Systems
The affected products are IBM MQ versions 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 LTS, and 10.0.0.0. IBM recommends applying the 9.3.0.42 cumulative security update to all 9.3 LTS installations, the 9.4.0.26 update to all 9.4 LTS installations, and upgrading 9.3 CD, 9.4 CD, and 10.0.0.0 installations to IBM MQ 10.0.0.5.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity. EPSS data is not available, andV catalog, but the high impact and lack of authentication required for exploitation strongly suggest the need for immediate remediation. The likely attack vector is an unauthenticated remote JNDI injection that can be triggered by a malicious client connecting to the MQ server.
OpenCVE Enrichment