CVE-2025-0975

CWE-1503 documents3 sources
Severity
8.8HIGH
EPSS
0.1%
top 66.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 28

Description

IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD console could allow an authenticated user to execute code due to improper neutralization of escape characters.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

NVDibm/mq_appliance9.3.09.4.2+2
CVEListV5ibm/mq9.3 LTS, 9.3 CD, 9.4 LTS, 9.4 CD

🔴Vulnerability Details

2
CVEList
IBM MQ code execution2025-02-28
GHSA
GHSA-r2vw-h337-2gxm: IBM MQ 92025-02-28
CVE-2025-0975 (HIGH CVSS 8.8) | IBM MQ 9.3 LTS | cvebase.io