CVE-2025-0975

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Feb 28, 2025
CWE ID 150

Summary

CVE-2025-0975 is a vulnerability affecting IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD console. An authenticated user can exploit this issue by improperly neutralizing escape characters, leading to the execution of arbitrary code. Successful exploitation may result in unauthorized system access or data manipulation. IBM recommends users to install the available patches to mitigate this risk. Unpatched systems remain vulnerable to this code injection vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share