Executive brief
IBM MQ for HPE NonStop is a message queueing system used for enterprise integration in mission-critical environments. An authenticated attacker can exploit improper validation of message header offsets to read sensitive data from memory or crash the service, causing business disruptions. The vulnerability requires valid credentials to exploit but poses significant risk to confidentiality and availability.
Technical details
The vulnerability is an out-of-bounds read (CWE-125) in message header processing due to improper validation of header offset values. Attack vector is network-based, requires authentication (PR:L), and no user interaction. An attacker can trigger information disclosure or denial of service. A patch is available via CSU 8.1.0.41.
Affected products
- IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40
Timeline
- 2026-09-17: disclosed
- 2026-09-17: patched: CSU 8.1.0.41 available