CVE-2024-25048: IBM MQ code execution
IBM MQ Appliance 9.3 CD and LTS are vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote authenticated attacker could overflow a buffer and execute arbitrary code on the system or cause the server to crash. IBM X-Force ID: 283137.
Other sources
IBM MQ is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote authenticated attacker could overflow a buffer and execute arbitrary code on the system or cause the server to crash.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25048?
CVE-2024-25048 is a critical vulnerability due to its potential for remote code execution and server crashes.
How do I fix CVE-2024-25048?
To fix CVE-2024-25048, update the IBM MQ Appliance to the latest version that addresses this vulnerability.
What types of attacks can CVE-2024-25048 facilitate?
CVE-2024-25048 can allow a remote authenticated attacker to perform arbitrary code execution or crash the server.
Which versions of IBM MQ Appliance are affected by CVE-2024-25048?
CVE-2024-25048 affects IBM MQ Appliance versions 9.3 CD and 9.3 LTS.
Who discovered CVE-2024-25048?
CVE-2024-25048 was identified by IBM X-Force and is assigned an X-Force ID of 283137.