CVE-2024-40681: IBM Mq Operator

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow an authenticated user in a specifically defined role, to bypass security restrictions and execute actions against the queue manager.

Affected products

  • IBM Mq Operator: from 2.0.0, up to and including 2.0.25; from 2.2.0, up to and including 2.2.2; from 2.3.0, up to and including 2.3.3; from 2.4.0, up to and including 2.4.8; from 3.1.0, up to and including 3.1.3; from 3.2.0, up to and including 3.2.3; …
  • IBM Supplied Mq Advanced Container Images: version 9.2.0.1 only; version 9.2.0.2 only; version 9.2.0.4 only; version 9.2.0.5 only; version 9.2.0.6 only; version 9.2.3.0 only; …

Published 2024-09-07. Last modified 2026-06-17.