CVE-2026-10853
7.5
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
IBM MQ could allow an authenticated attacker with cluster access to cause a denial of service or potentially execute arbitrary code due to improper validation of cluster command message lengths.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| IBM | MQ | 9.1.0.0 <= 9.1.0.37 LTS | affected |
| IBM | MQ | 9.2.0.0 <= 9.2.0.43 LTS | affected |
| IBM | MQ | 9.3.0.0 <= 9.3.0.41 LTS | affected |
| IBM | MQ | 9.3.0.0 <= 9.3.5.1 CD | affected |
| IBM | MQ | 9.4.0.0 <= 9.4.0.25 LTS | affected |
| IBM | MQ | 9.4.0.0 <= 9.4.5.1 CD | affected |
| IBM | MQ | 10.0.0.0 | affected |
Weaknesses
- CWE-470: CWE-470 Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.