ZeroHour

CVE-2026-12354

moderate

Authenticated RCE via JNDI Injection in IBM MQ Resource Adapter IVT App

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

IBM MQ ships a Resource Adapter Installation Verification Test (IVT) application that improperly validates JNDI names (CWE-913), allowing an authenticated attacker with network access to supply a malicious JNDI lookup and achieve arbitrary code execution on the application server hosting the resource adapter, in a Log4Shell-style pattern. Exploitation requires valid credentials (PR:L) and somewhat difficult conditions (AC:H), but success yields high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.5). Every currently shipped release stream is affected, from 9.1 LTS through 9.2, 9.3, and 9.4 LTS/CD up to 10.0.0.0. No public proof of concept exists and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, so exploitation is presumed unlikely at this time.

What to do: Upgrade to the newest fix pack IBM has published for your release stream — anything beyond the affected ranges listed above — and prioritize migration off the aging 9.1/9.2 LTS streams, which are at or near end of support. If the Resource Adapter Installation Verification Test application is not required in production, undeploy or disable it, restrict authenticated access to it, and limit the application server's ability to make outbound JNDI/LDAP/RMI connections. Review application server logs for unexpected JNDI lookups or outbound directory traffic as an indicator of attempted exploitation.

Affected
IBM MQ9.1.0.0 through 9.1.0.37 LTS
IBM MQ9.2.0.0 through 9.2.0.43 LTS
IBM MQ9.3.0.0 through 9.3.0.41 LTS
IBM MQ9.3.0.0 through 9.3.5.1 CD
IBM MQ9.4.0.0 through 9.4.0.25 LTS
IBM MQ9.4.0.0 through 9.4.5.1 CD
IBM MQ10.0.0.0
Estimated exposure
moderatetens of thousands of enterprise deployments worldwide; only a few thousand internet-exposed endpoints — IBM MQ is a staple messaging platform in banking and large enterprises (typically tens of thousands of licensed queue-manager deployments), but it is usually deployed on internal networks and this flaw additionally requires authenticated…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to execute arbitrary code on the application server due to improper validation of JNDI names in the Resource Adapter Installation Verification Test application.

Weakness
CWE-913
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.