Impact
IBM MQ versions 9.1 through 10.0 expose an authenticated attacker to arbitrary code execution by deserializing untrusted data. This is an insecure deserialization flaw, identified as CWE-502. The vulnerability allows a privileged user to inject malicious payloads that are processed by the MQ server, enabling the attacker to run arbitrary code with the privileges of the MQ process. This can lead to full system compromise and significant confidentiality, integrity, and availability impacts. The CVSS score of 8.8 attests to its high severity.
Affected Systems
IBM MQ is affected. Impacted releases include IBM MQ 9.1 LTS from build 9.1.0.0 through 9.1.0.37, 9.2 LTS from 9.2.0.0 through 9.2.0.43, 9.3 LTS from 9.3.0.0 through 9.3.0.41 and 9.3.5.1 CD, 9.4 LTS from 9.4.0.0 through 9.4.0.25 and 9.4.5.1 CD, and IBM MQ 10.0.0.0. The advisory lists specific cumulative security updates for each version that contain the fix.
Risk and Exploitability
It is not listed in the CISA KEV catalog, but its EPSS score of < 1% indicates a very low but non‑zero exploitation probability. The high CVSS score signals a strong potential attack. Because authentication is required, the risk primarily applies to environments where valid credentials or compromised accounts exist. Based on the description, the likely attack vector is a remote client connection that sends crafted serialized objects to the MQ server over the standard MQ client protocol, requiring authenticated credentials. Exploitation would need an attacker to send these crafted objects, which is feasible over a remote connection. Given the severity, security teams should consider the exposure high until a patch is applied.
OpenCVE Enrichment