CVE-2019-4719: IBM Mq

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD could allow a local attacker to obtain sensitive information by inclusion of sensitive data within runmqras data.

Affected products

  • IBM Mq: from 8.0.0.0, before 8.0.0.14 (fixed in 8.0.0.14); from 9.0.0.0, up to and including 9.0.0.9; from 9.1.0, before 9.1.4 (fixed in 9.1.4); from 9.1.0.0, before 9.1.0.4 (fixed in 9.1.0.4)
  • IBM Mq Appliance: from 8.0.0.0, before 8.0.0.14 (fixed in 8.0.0.14); from 9.1.0, before 9.1.4 (fixed in 9.1.4); from 9.1.0.0, before 9.1.0.4 (fixed in 9.1.0.4)
  • IBM WebSphere Mq: from 7.1.0.0, up to and including 7.5.0.9

Published 2020-03-16. Last modified 2026-06-17.