IBM MQ 9.1, 9.2, 9.3, 9.4 LTS and 9.3, 9.4 CD is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations. By conducting slowloris-type attacks, a remote attacker could exploit this vulnerability to cause a denial of service.
2025-10-16T17:15:33.547
2025-10-28T16:53:08.540
Analyzed
CVSSv3.1: 7.5 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | ibm | mq | 9.1.0.0 | Yes |
| Application | ibm | mq | 9.2.0.0 | Yes |
| Application | ibm | mq | 9.3.0 | Yes |
| Application | ibm | mq | 9.3.0.0 | Yes |
| Application | ibm | mq | 9.4.0 | Yes |
| Application | ibm | mq | 9.4.0.0 | Yes |
| Operating System | ibm | aix | - | No |
| Operating System | ibm | i | - | No |
| Operating System | linux | linux_kernel | - | No |
| Operating System | microsoft | windows | - | No |
| Operating System | oracle | solaris | - | No |