IBM MQ Authority Vulnerability Allowing Access to SYSTEM.AUTH.DATA.QUEUE

Vulnerability

An authority vulnerability has been identified in IBM MQ versions 9.1.0.0 through 9.1.0.33 LTS, 9.2.0.0 through 9.2.0.40 LTS, 9.3.0.0 through 9.3.0.36 LTS, 9.30.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.17 LTS, and 9.4.0.0 through 9.4.4.1 CD. This vulnerability allows users to access the SYSTEM.AUTH.DATA.QUEUE.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive data in the SYSTEM.AUTH.DATA.QUEUE.

Remediation

Users can upgrade to IBM MQ version 9.1.0.34, 9.2.0.41, 9.3.0.37, or 9.4.0.20. For IBM MQ versions 9.3 CD and 9.4 CD, upgrade to version 9.4.5.0 or later.

Added: Mar 3, 2026, 9:20 PM
Updated: Mar 3, 2026, 9:56 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
5.0
exploitability
3.5
remediation
7.7
relevance
3.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.