CVE-2025-23225: IBM MQ denial of service
IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow an authenticated user to cause a denial of service due to the improper handling of invalid headers sent to the queue.
Other sources
IBM MQ could allow an authenticated user to cause a denial of service due to the improper handling of invalid headers sent to the queue.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-23225?
CVE-2025-23225 has a high severity level due to its potential to cause denial of service.
How do I fix CVE-2025-23225?
To fix CVE-2025-23225, ensure you update IBM MQ to a patched version that addresses the vulnerability.
Who is affected by CVE-2025-23225?
CVE-2025-23225 affects IBM MQ versions 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD.
What types of attacks can exploit CVE-2025-23225?
CVE-2025-23225 can be exploited by authenticated users to send invalid headers and trigger a denial of service.
Is there a workaround for CVE-2025-23225?
Currently, there are no known workarounds for CVE-2025-23225 other than applying the appropriate patches.