CVE-2024-25015: IBM Mq
High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.
IBM MQ 9.2 LTS, 9.3 LTS, and 9.3 CD Internet Pass-Thru could allow a remote user to cause a denial of service by sending HTTP requests that would consume all available resources. IBM X-Force ID: 281278.
Affected products
- IBM Mq: from 9.2.0.0, before 9.2.0.25 (fixed in 9.2.0.25); from 9.3.0, before 9.3.5 (fixed in 9.3.5); from 9.3.0.0, before 9.3.0.17 (fixed in 9.3.0.17)
Published 2024-05-01. Last modified 2026-06-17.