CVE-2024-27256: IBM Mq Operator

High severity, CVSS 7.5. EPSS: 0.2% chance of exploitation in the next 30 days.

IBM MQ Container 3.0.0, 3.0.1, 3.1.0 through 3.1.3 CD, 2.0.0 LTS through 2.0.22 LTS and 2.4.0 through 2.4.8, 2.3.0 through 2.3.3, 2.2.0 through 2.2.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

Affected products

  • IBM Mq Operator: from 2.0.0, up to and including 2.0.22; from 2.2.0, up to and including 2.2.2; from 2.3.0, up to and including 2.3.3; from 2.4.0, up to and including 2.4.8; from 3.1.0, up to and including 3.1.3; version 3.0.0 only; …
  • IBM Supplied Mq Advanced Container Images: version 9.2.0.1 only; version 9.2.0.2 only; version 9.2.0.4 only; version 9.2.0.5 only; version 9.2.0.6 only; version 9.2.3.0 only; …

Published 2025-01-27. Last modified 2026-06-17.