6.5
CVE-2025-23225
- EPSS 0.12%
- Published 28.02.2025 03:15:10
- Last modified 03.07.2025 20:25:35
- Source psirt@us.ibm.com
- Teams watchlist Login
- Open Login
IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow an authenticated user to cause a denial of service due to the improper handling of invalid headers sent to the queue.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users. Login
Data is provided by the National Vulnerability Database (NVD)
Ibm ≫ Mq Appliance SwEditioncontinuous_delivery Version <= 9.4.2
Ibm ≫ Mq Appliance SwEditionlts Version >= 9.3.0.0 <= 9.3.0.27
Ibm ≫ Mq Appliance SwEditionlts Version >= 9.4.0.0 <= 9.4.0.10
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.12% | 0.309 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
psirt@us.ibm.com | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
|
CWE-230 Improper Handling of Missing Values
The product does not handle or incorrectly handles when a parameter, field, or argument name is specified, but the associated value is missing, i.e. it is empty, blank, or null.