Impact
The vulnerability involves improper input validation in IBM MQ's IVT servlet, allowing an attacker to inject a JNDI reference. The servlet accepts crafted input fragments without proper sanitization, which can cause the application to resolve or bind to arbitrary JNDI resources. The flaw can lead to disclosure of configuration or data, and if the attacker supplies malicious code, remote code execution is possible. This injection flaw is identified as CWE‑74.
Affected Systems
IBM MQ versions 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.5.1 (both LTS and CD), 9.4.0.0 through 9.4.5.1, and 10.0.0.0 are affected. The vulnerable IVT servlet is exposed over the network and can be accessed without authentication by an external attacker, potentially on any system running these product versions.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity with remote code execution potential. The EPSS score is reported as < 1%, reflecting a low yet non-zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Assuming network reachability to the IVT servlet endpoint, an attacker who can supply arbitrary request data could trigger the injection, potentially compromising the host and the MQ service. Prompt remediation is therefore recommended.
OpenCVE Enrichment