Security Bulletin: IBM MQ Appliance is affected by a denial of service vulnerability (CVE-2025-27365)

Vulnerability Details

Basic Information

Title Security Bulletin: IBM MQ Appliance is affected by a denial of service vulnerability (CVE-2025-27365)
Type ibm
Published 2025-05-02T15:15:11
Last Seen 2025-05-02T18:56:39
CVSS Score 6.5 (MEDIUM)

CVSS v3 Details

Attack Vector NETWORK
Attack Complexity LOW
Privileges Required LOW
User Interaction NONE
Scope UNCHANGED
Confidentiality Impact NONE
Integrity Impact NONE
Availability Impact HIGH

CVE Information

CVE IDs CVE-2025-27365
CWE
Bulletin Family software

Description

## Summary

IBM MQ Appliance has resolved a denial of service vulnerability.

## Vulnerability Details

**CVEID:**CVE-2025-27365
**DESCRIPTION:** An IBM MQ client connecting to an IBM MQ queue manager can cause a SIGSEGV in the AMQRMPPA channel process terminating it.
**CWE:**CWE-416: Use After Free
**CVSS Source:** IBM
**CVSS Base score:** 6.5
**CVSS Vector:**(CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)

## Affected Products and Versions

Affected Product(s) | Version(s)
—|—
IBM MQ Appliance | 9.3 CD – 9.3.3.0 to 9.3.5.2
IBM MQ Appliance | 9.4 LTS – 9.4.0.0 to 9.4.0.10
IBM MQ Appliance | 9.4 CD – 9.4.1.0 to 9.4.2.0

## Remediation/Fixes

This vulnerability is addressed under APAR IT47591

IBM strongly recommends addressing the vulnerability now.

**IBM MQ Appliance version 9.3 CD**

Upgrade to IBM MQ Appliance cumulative security update 9.4.0.11, or later firmware.

**IBM MQ Appliance version 9.4 LTS**

Apply IBM MQ Appliance cumulative security update 9.4.0.11, or later firmware.

**IBM MQ Appliance version 9.4 CD**

Apply IBM MQ Appliance cumulative security update 9.4.2.1, or later firmware.

## Workarounds and Mitigations

None

##

Impact Assessment

Base Score 6.5
Severity MEDIUM

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.