What happened
IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication.
Affected versions
MQ Appliance: 9.4 LTS through 9.4.0.0 to 9.4.0.25 (custom); 9.4 CD through 9.4.1.0 to 9.4.5.2 (custom); 10.0.0.0 through 10.0.0.1 only (semver) Fixed: See vendor advisory.
Why it matters
Review the vendor advisory and exposure of the affected product to determine operational impact.
Detection & mitigation
- Apply vendor-provided updates or mitigations.
- Review affected product exposure and access logs.
Public PoC references
No public PoC reference has passed the current publication threshold.
Source timeline
CVE record published by NVDView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.