CVE-2025-3631: IBM Mq Appliance

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

An IBM MQ 9.3 and 9.4 Client connecting to an MQ Queue Manager can cause a SIGSEGV in the AMQRMPPA channel process terminating it.

Affected products

  • IBM Mq Appliance: from 9.3.2, up to and including 9.3.5.2; from 9.4.0.0, before 9.4.0.12 (fixed in 9.4.0.12); from 9.4.0.0, before 9.4.3 (fixed in 9.4.3); from 9.4.1.0, before 9.4.3.0 (fixed in 9.4.3.0)

Published 2025-07-11. Last modified 2026-06-17.