IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication.
This vulnerability is addressed under APAR DT472411
IBM strongly recommends addressing the vulnerability now.
IBM MQ Appliance version 9.4 LTS
Apply IBM MQ Appliance fix pack 9.4.0.26 https://www.ibm.com/support/fixcentral/swg/selectFixes , or later firmware.
IBM MQ Appliance version 9.4 CD - M2003
Upgrade to IBM MQ Appliance 10.0.0.5 https://www.ibm.com/support/fixcentral/swg/selectFixes , or later firmware.
IBM MQ Appliance version 9.4 CD - M2002
Apply IBM MQ Appliance cumulative security update 9.4.5.3 https://www.ibm.com/support/fixcentral/swg/selectFixes , or later firmware.
IBM MQ Appliance version 10 LTS
Apply IBM MQ Appliance fix pack 10.0.0.5 https://www.ibm.com/support/fixcentral/swg/selectFixes , or later firmware.