Impact
The vulnerability resides in the Resource Adapter Installation Verification Test application of IBM MQ. Incorrect validation of JNDI names allows an attacker who has authenticated access to supply a crafted name that causes the application server to resolve and load untrusted code. This flaw is classified as CWE‑913 and can lead to arbitrary code execution with the privileges of the application server, compromising confidentiality, integrity, and availability of the affected environment.
Affected Systems
IBM MQ versions from 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 are affected. IBM provides cumulative security updates for each major LTS release—9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26—and recommends upgrading to IBM MQ 10.0.0.5 for systems still running 10.0.0.0 or CD builds.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, while an EPSS of less than 1% suggests a very low exploitation likelihood under current conditions. Although not yet listed in the CISA KEV catalog, the vulnerability remains a significant threat for installations that have not applied the fix because it requires only legitimate authenticated access—which is common in many MQ deployments—and can immediately lead to complete server compromise. There is no publicly documented exploit, but the remote code execution path demonstrates the potential for severe impact if an attacker gains proper credentials.
OpenCVE Enrichment