IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD console could allow an authenticated user to execute code due to improper neutralization of escape characters.
2025-02-28T03:15:10.653
2025-07-03T20:41:35.323
Analyzed
CVSSv3.1: 8.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ibm | mq_appliance | ≤ 9.4.2 | Yes |
Application | ibm | mq_appliance | ≤ 9.3.0.27 | Yes |
Application | ibm | mq_appliance | ≤ 9.4.0.10 | Yes |