CVE-2025-0975: IBM MQ code execution
IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD console could allow an authenticated user to execute code due to improper neutralization of escape characters.
Other sources
IBM MQ console could allow an authenticated user to execute code due to improper neutralization of escape characters.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0975?
CVE-2025-0975 is considered to have a high severity due to the potential for authenticated users to execute arbitrary code.
How do I fix CVE-2025-0975?
To mitigate CVE-2025-0975, ensure to apply the latest security patches provided by IBM for affected versions of MQ.
Which versions are affected by CVE-2025-0975?
CVE-2025-0975 affects IBM MQ versions 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD along with several specific container image versions.
What can exploit CVE-2025-0975?
CVE-2025-0975 can be exploited by authenticated users who can manipulate escape characters to execute arbitrary code on the system.
Is CVE-2025-0975 a remote or local vulnerability?
CVE-2025-0975 is a local vulnerability that requires an authenticated user in order to exploit the improper neutralization of escape characters.