[WID-SEC-2026-3307] IBM MQ Appliance (Axios Node.js): Mehrere Schwachstellen CVSS Base Score 8.7 (hoch) CVSS Temporal Score 7.6 (hoch) Remoteangriff ja Datum 10.09.2026 Stand 11.09.2026 Mitigation ja Betroffene Systeme Betriebssystem BIOS/Firmware Sonstiges UNIX Windows Produktbeschreibung IBM MQ ist eine Message Oriented Middleware von IBM. Produkte 10.09.2026 IBM MQ Appliance <9.4.0.26 IBM MQ Appliance <9.4.5.3 IBM MQ Appliance <10.0.0.5 Angriff Angriff Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM MQ Appliance ausnutzen, um beliebigen Programmcode auszuführen, Server-Side Request Forgery (SSRF) durchzuführen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder Denial-of-Service-Zustände herbeizuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben
Multiple vulnerabilities in the Axios Node.js component of IBM MQ Appliance (CVSS Base Score 8.7) allow a remote, anonymous attacker to execute arbitrary code, perform SSRF, manipulate data, disclose information, or cause denial-of-service. Affected versions are IBM MQ Appliance before 9.4.0.26, before 9.4.5.3, and before 10.0.0.5. A mitigation is available, and users should apply the relevant patches to these fixed versions.