Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
This vulnerability is addressed under APAR DT472411 IBM strongly recommends addressing the vulnerability now. IBM MQ Appliance version 9.4 LTS Apply IBM MQ Appliance fix pack 9.4.0.26 https://www.ibm.com/support/fixcentral/swg/selectFixes , or later firmware. IBM MQ Appliance version 9.4 CD - M2003 Upgrade to IBM MQ Appliance 10.0.0.5 https://www.ibm.com/support/fixcentral/swg/selectFixes , or later firmware. IBM MQ Appliance version 9.4 CD - M2002 Apply IBM MQ Appliance cumulative security update 9.4.5.3 https://www.ibm.com/support/fixcentral/swg/selectFixes , or later firmware. IBM MQ Appliance version 10 LTS Apply IBM MQ Appliance fix pack 10.0.0.5 https://www.ibm.com/support/fixcentral/swg/selectFixes , or later firmware.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7284690 |
|
Fri, 18 Sep 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication. | |
| Title | IBM MQ Appliance is affected by a heap buffer overflow vulnerability in protocol message processing | |
| First Time appeared |
Ibm
Ibm mq Appliance |
|
| Weaknesses | CWE-122 | |
| CPEs | cpe:2.3:a:ibm:mq_appliance:10.0.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:mq_appliance:10.0.0.1:*:*:*:*:*:*:* cpe:2.3:a:ibm:mq_appliance:9.4.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:mq_appliance:9.4.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:mq_appliance:9.4.1.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:mq_appliance:9.4:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm mq Appliance |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-09-18T15:55:43.394Z
Reserved: 2026-06-03T13:39:03.419Z
Link: CVE-2026-10747
No data.
Status : Awaiting Analysis
Published: 2026-09-18T16:17:04.413
Modified: 2026-09-18T18:17:47.257
Link: CVE-2026-10747
No data.
OpenCVE Enrichment
No data.