Impact
IBM MQ is vulnerable due to a flaw that allows a remote authenticated attacker to deserialise untrusted data and execute arbitrary code on the host. The weakness is caused by insecure handling of deserialized objects valid credentials to inject malicious payloads and gain full control of the system.
Affected Systems
Versions of IBM MQ from 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS and CD, 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS and CD, 9.4.5.1 CD, and 10.0.0.0 are affected. The vulnerability applies to all builds within these major releases, including both long‑term support and current development builds.
Risk and Exploitability
The CVSS score of 8.8 indicates high impact with medium‑to‑high likelihood for a successful exploit. The EPSS score is under 1%, indicating a very low but non‑zero probability of exploitation, although the precise exploitation frequency remains unclear. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote over the MQ network when an authenticated client submits a crafted payload; the prerequisite is a valid user credential. An attacker who succeeds could execute arbitrary code on the MQ server, potentially leading to full system compromise.
OpenCVE Enrichment