CVE-2024-35156: IBM Mq

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

IBM MQ 9.3 LTS and 9.3 CD could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 292766.

Affected products

  • IBM Mq: from 9.3.0.0, before 9.3.0.20 (fixed in 9.3.0.20); from 9.3.0.0, before 9.4.0.0 (fixed in 9.4.0.0)

Published 2024-06-28. Last modified 2026-06-17.