← Vulnerability feed

Vulnerability record · CVE-2025-0975 · published 28 February 2025

CVE-2025-0975: Ibm mq appliance vulnerability

Ibm · Mq Appliance

IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD console could allow an authenticated user to execute code due to improper neutralization of escape characters.

8.8 CVSS 3.1 High EPSS 0.68% · top 49.6% CWE-150 · CWE-150
8.8CVSS 3.1 base score
0.68%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD console could allow an authenticated user to execute code due to improper neutralization of escape characters.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-0975 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-4682Ibm mq deserialization of untrusted data vulnerabilityIBM MQ 7.5, 8.0, 9.0, 9.1, 9.2 LTS, and 9.2 CD could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserializa…EPSS 7.8%8.8CVE-2020-4938Ibm mq appliance cross-site request forgery vulnerabilityIBM MQ Appliance 9.1 and 9.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions …EPSS 0.40%8.8CVE-2017-1318Ibm mq appliance os command injection vulnerabilityIBM MQ Appliance 8.0 and 9.0 could allow an authenticated messaging administrator to execute arbitrary commands on the system, caused by command exec…EPSS 3.1%7.8CVE-2023-46176Ibm mq appliance vulnerabilityIBM MQ Appliance 9.3 CD could allow a local attacker to gain elevated privileges on the system, caused by improper validation of security keys. IBM X…EPSS 0.18%7.8CVE-2019-4620Ibm mq appliance improper input validation vulnerabilityIBM MQ Appliance 8.0 and 9.0 LTS could allow a local attacker to bypass security restrictions caused by improper validation of environment variables.…EPSS 0.35%7.8CVE-2019-4294Ibm datapower gateway os command injection vulnerabilityIBM DataPower Gateway 2018.4.1.0 through 2018.4.1.6, 7.6.0.0 through 7.6.0.15 and IBM MQ Appliance 8.0.0.0 through 8.0.0.12, 9.1.0.0 through 9.1.0.2,…EPSS 0.95%7.5CVE-2025-3631Ibm mq appliance use after free vulnerabilityAn IBM MQ 9.3 and 9.4 Client connecting to an MQ Queue Manager can cause a SIGSEGV in the AMQRMPPA channel process terminating it.EPSS 0.33%7.5CVE-2024-25048Ibm mq appliance heap-based buffer overflow vulnerabilityIBM MQ Appliance 9.3 CD and LTS are vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote authenticated attacker c…EPSS 0.90%

Source: NIST National Vulnerability Database (record CVE-2025-0975), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.