cbcvebase.
CVE-2024-25015
published 2024-05-01

CVE-2024-25015: IBM MQ 9.2 LTS, 9.3 LTS, and 9.3 CD Internet Pass-Thru could allow a remote user to cause a denial of service by sending HTTP requests that would consume all…

PriorityP336high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.92%
56.4th percentile
IBM MQ 9.2 LTS, 9.3 LTS, and 9.3 CD Internet Pass-Thru could allow a remote user to cause a denial of service by sending HTTP requests that would consume all available resources. IBM X-Force ID: 281278.

Affected

4 ranges
VendorProductVersion rangeFixed in
ibmmq
ibmmq>= 9.2.0.0 < 9.2.0.259.2.0.25
ibmmq>= 9.3.0 < 9.3.59.3.5
ibmmq>= 9.3.0.0 < 9.3.0.179.3.0.17
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.