8.8

CVE-2026-10853

IBM MQ queue manager is vulnerable to remote code execution

IBM MQ could allow an authenticated attacker with cluster access to cause a denial of service or potentially execute arbitrary code due to improper validation of cluster command message lengths.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Mq SwEdition lts Version >= 9.1.0.0 <= 9.1.0.37
Ibm ≫ Mq SwEdition lts Version >= 9.2.0.0 <= 9.2.0.43
Ibm ≫ Mq SwEdition lts Version >= 9.3.0.0 <= 9.3.0.41
Ibm ≫ Mq SwEdition continuous_delivery Version >= 9.3.0.0 <= 9.3.5.1
Ibm ≫ Mq SwEdition lts Version >= 9.4.0.0 <= 9.4.0.25
Ibm ≫ Mq SwEdition continuous_delivery Version >= 9.4.0.0 <= 9.4.5.1
Ibm ≫ Mq Version 10.0.0.0 SwEdition continuous_delivery
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.36% 0.293
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
IBM 7.5 1.6 5.9
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-470 Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

The product uses external input with reflection to select which classes or code to use, but it does not sufficiently prevent the input from selecting improper classes or code.

https://www.ibm.com/support/pages/node/7284905
Patch
Vendor Advisory