CVE-2025-23225
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Feb 28, 2025
CWE ID 230
Summary
CVE-2025-23225 is a denial-of-service vulnerability affecting IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD. An authenticated user can exploit this issue by sending invalid headers to the queue, leading to improper handling and resulting in a service disruption. This vulnerability poses a risk to the availability of affected systems, potentially disrupting critical business operations. IBM urges users to apply the available patch as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- IBM MQ
Affected Vendors
- IBM Corporation