CVE-2025-0975

HIGH

IBM MQ Appliance 9.3.0-9.3.0.26 and 9.4.0-9.4.1 - Authenticated Remote Code Execution via Escape Character Injection

Title source: llm
STIX 2.1

Description

IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD console could allow an authenticated user to execute code due to improper neutralization of escape characters.

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory
https://www.ibm.com/support/pages/node/7183467

Scores

CVSS v3 8.8
EPSS 0.0014
EPSS Percentile 33.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-150
Status published
Products (2)
ibm/mq_appliance 9.3.0 - 9.4.2
ibm/mq_appliance 9.3.0.0 - 9.3.0.27
Published Feb 28, 2025
Tracked Since Feb 18, 2026