CVE-2025-23225
IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow an authenticated user to cause a denial of service due to the improper handling of invalid headers sent to the queue.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS probability
- 0.43%
- CWE
- CWE-230
- Published
- 2025-02-28
- Last modified
- 2026-03-13
Affected products
- IBM MQ
Weakness type
Related vulnerabilities
- CVE-2026-25659 — Ericsson Packet Core Gateway (PCG) - Improper handling of missing values Vulnerability
- CVE-2026-25658 — Ericsson Packet Core Gateway (PCG) - Improper handling of missing values Vulnerability
- CVE-2026-20086 — A vulnerability in the processing of Control and Provisioning of Wireless Access Points (CAPWAP)...
- CVE-2026-1461 — Simple Membership <= 4.7.0 - Unauthenticated Improper Handling of Missing Values
- CVE-2024-11024 — AppPresser – Mobile App Framework <= 4.4.6 - Unauthenticated Privilege Escalation via Password Reset
- CVE-2024-10508 — RegistrationMagic – User Registration Plugin with Custom Registration Forms <= 6.0.2.6 - Unauthenticated Privilege Escalation via Password Recovery
- CVE-2024-9781 — Improper Handling of Missing Values in Wireshark
- CVE-2024-6237 — 389-ds-base: unauthenticated user can trigger a dos by sending a specific extended search request