CVE-2024-39742: IBM Mq Operator

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

IBM MQ Operator 3.2.2 and IBM MQ Operator 2.0.24 could allow a user to bypass authentication under certain configurations due to a partial string comparison vulnerability. IBM X-Force ID: 297169.

Affected products

  • IBM Mq Operator: from 2.0.0, before 2.0.24 (fixed in 2.0.24); from 2.2.0, up to and including 2.2.2; from 2.3.0, up to and including 2.3.3; from 2.4.0, up to and including 2.4.8; from 3.1.0, up to and including 3.1.3; from 3.2.0, before 3.2.2 (fixed in 3.2.2); …

Published 2024-07-08. Last modified 2026-06-17.