What happened
IBM MQ 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 LTS, and 10.0.0.0 could allow a remote attacker to execute arbitrary code due to unsafe JNDI lookup processing when the IVT application is deployed.
Affected versions
MQ: 9.3.0.0 through 9.3.0.41 LTS (semver); 9.3.0.0 through 9.3.5.1 CD (semver); 9.4.0.0 through 9.4.0.25 LTS (semver); 9.4.0.0 through 9.4.5.1 LTS (semver); 10.0.0.0 Fixed: See vendor advisory.
Why it matters
Review the vendor advisory and exposure of the affected product to determine operational impact.
Detection & mitigation
- Apply vendor-provided updates or mitigations.
- Review affected product exposure and access logs.
Public PoC references
No public PoC reference has passed the current publication threshold.