CVE-2025-0975
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Feb 28, 2025
CWE ID 150
Summary
CVE-2025-0975 is a vulnerability affecting IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD console. An authenticated user can exploit this issue by improperly neutralizing escape characters, leading to the execution of arbitrary code. Successful exploitation may result in unauthorized system access or data manipulation. IBM recommends users to install the available patches to mitigate this risk. Unpatched systems remain vulnerable to this code injection vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- IBM MQ
Affected Vendors
- IBM Corporation