CVE-2026-11727: IBM MQ for HPE NonStop is vulnerable to a denial of service issue
IBM MQ C client could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of queue manager responses when requesting AMS policy data.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM MQ for HPE NonStop 8.1.0 (CSU)to a version that resolves this vulnerability.Fixed in 8.1.0.41Patch IT49921
Event History
Frequently Asked Questions
Which deployments are affected?
The affected component is the IBM MQ C client in IBM MQ for HPE NonStop versions 8.1.0 through 8.1.0.40. Exposure is tied to clients requesting AMS policy data from a queue manager.
What must an attacker be able to do to exploit this issue?
The issue is remotely exploitable without privileges or user interaction, but the attack complexity is rated high. Exploitation involves supplying improperly validated queue manager responses during an AMS policy data request.
What is the potential impact?
A successful attack may cause a denial of service and could potentially result in arbitrary code execution. Confidentiality, integrity, and availability are each rated high in the supplied severity vector.