Executive brief
IBM MQ is enterprise messaging middleware used to reliably route and process business data across applications and systems. A deserialization filter bypass in the MQ Java and JMS client libraries allows an authenticated attacker to execute arbitrary code on client applications, potentially compromising data confidentiality, integrity, and system availability. This affects multiple versions across IBM's supported product lines.
Technical details
The vulnerability is a deserialization filter bypass (CWE-502) in the Java and JMS client libraries, specifically in exception handling code. An authenticated attacker with network access can craft malicious serialized objects that bypass the deserialization filter, leading to arbitrary code execution on systems running affected client libraries. The attack requires authentication and has high complexity, but succeeds without user interaction. Patches are available for all supported versions: 9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26, and 10.0.0.5 or later.
Affected products
- IBM MQ 9.1.0.0–9.1.0.37 LTS, 9.2.0.0–9.2.0.43 LTS, 9.3.0.0–9.3.0.41 LTS, 9.3.0.0–9.3.5.1 CD, 9.4.0.0–9.4.0.25 LTS, 9.4.0.0–9.4.5.1 CD, 10.0.0.0
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched: Patches available: 9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26, 10.0.0.5