CVE-2019-4620: IBM Mq Appliance

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

IBM MQ Appliance 8.0 and 9.0 LTS could allow a local attacker to bypass security restrictions caused by improper validation of environment variables. IBM X-Force ID: 168863.

Affected products

  • IBM Mq Appliance: from 8.0.0.0, before 8.0.0.14 (fixed in 8.0.0.14); from 9.1.0, before 9.1.4 (fixed in 9.1.4); from 9.1.0.0, before 9.1.0.4 (fixed in 9.1.0.4)

Published 2020-01-28. Last modified 2026-06-17.