CVE-2024-25015: IBM Mq

High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.

IBM MQ 9.2 LTS, 9.3 LTS, and 9.3 CD Internet Pass-Thru could allow a remote user to cause a denial of service by sending HTTP requests that would consume all available resources. IBM X-Force ID: 281278.

Affected products

  • IBM Mq: from 9.2.0.0, before 9.2.0.25 (fixed in 9.2.0.25); from 9.3.0, before 9.3.5 (fixed in 9.3.5); from 9.3.0.0, before 9.3.0.17 (fixed in 9.3.0.17)

Published 2024-05-01. Last modified 2026-06-17.