CVE-2026-12355
EUVD-2026-7887715.09.2026, 18:17
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an attacker to perform JNDI injection attacks due to insufficient input validation, potentially leading to information disclosure or remote code execution.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| ibm | mq | 9.1.0.0 ≤ | CNA |
| ibm | mq | 9.2.0.0 ≤ | CNA |
| ibm | mq | 9.3.0.0 ≤ | CNA |
| ibm | mq | 9.4.0.0 ≤ | CNA |
| ibm | mq | 10.0.0.0 | CNA |