← Vulnerability feed

Vulnerability record · CVE-2025-3631 · published 11 July 2025

CVE-2025-3631: Ibm mq appliance use after free vulnerability

Ibm · Mq Appliance

An IBM MQ 9.3 and 9.4 Client connecting to an MQ Queue Manager can cause a SIGSEGV in the AMQRMPPA channel process terminating it.

7.5 CVSS 3.1 High EPSS 0.33% · top 76.2% CWE-416 · Use after free
7.5CVSS 3.1 base score
0.33%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An IBM MQ 9.3 and 9.4 Client connecting to an MQ Queue Manager can cause a SIGSEGV in the AMQRMPPA channel process terminating it.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-3631 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-4682Ibm mq deserialization of untrusted data vulnerabilityIBM MQ 7.5, 8.0, 9.0, 9.1, 9.2 LTS, and 9.2 CD could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserializa…EPSS 7.8%8.8CVE-2025-0975Ibm mq appliance vulnerabilityIBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD console could allow an authenticated user to execute code due to improper neutralization of escape charac…EPSS 0.68%8.8CVE-2020-4938Ibm mq appliance cross-site request forgery vulnerabilityIBM MQ Appliance 9.1 and 9.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions …EPSS 0.40%8.8CVE-2017-1318Ibm mq appliance os command injection vulnerabilityIBM MQ Appliance 8.0 and 9.0 could allow an authenticated messaging administrator to execute arbitrary commands on the system, caused by command exec…EPSS 3.1%7.8CVE-2023-46176Ibm mq appliance vulnerabilityIBM MQ Appliance 9.3 CD could allow a local attacker to gain elevated privileges on the system, caused by improper validation of security keys. IBM X…EPSS 0.18%7.8CVE-2019-4620Ibm mq appliance improper input validation vulnerabilityIBM MQ Appliance 8.0 and 9.0 LTS could allow a local attacker to bypass security restrictions caused by improper validation of environment variables.…EPSS 0.35%7.8CVE-2019-4294Ibm datapower gateway os command injection vulnerabilityIBM DataPower Gateway 2018.4.1.0 through 2018.4.1.6, 7.6.0.0 through 7.6.0.15 and IBM MQ Appliance 8.0.0.0 through 8.0.0.12, 9.1.0.0 through 9.1.0.2,…EPSS 0.95%7.5CVE-2024-25048Ibm mq appliance heap-based buffer overflow vulnerabilityIBM MQ Appliance 9.3 CD and LTS are vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote authenticated attacker c…EPSS 0.90%

Source: NIST National Vulnerability Database (record CVE-2025-3631), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.