{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-12354","assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","state":"PUBLISHED","assignerShortName":"ibm","dateReserved":"2026-06-15T21:42:00.609Z","datePublished":"2026-09-15T17:13:11.614Z","dateUpdated":"2026-09-16T03:56:36.302Z"},"containers":{"cna":{"providerMetadata":{"orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm","dateUpdated":"2026-09-15T17:13:11.614Z"},"title":"IBM MQ Resource Adapter IVT message-driven bean is vulnerable to remote code execution via JNDI injection","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-913","description":"CWE-913 Improper Control of Dynamically-Managed Code Resources","type":"CWE"}]}],"affected":[{"vendor":"IBM","product":"MQ","versions":[{"status":"affected","version":"9.1.0.0","lessThanOrEqual":"9.1.0.37 LTS","versionType":"semver"},{"status":"affected","version":"9.2.0.0","lessThanOrEqual":"9.2.0.43 LTS","versionType":"semver"},{"status":"affected","version":"9.3.0.0","lessThanOrEqual":"9.3.0.41 LTS","versionType":"semver"},{"status":"affected","version":"9.3.0.0","lessThanOrEqual":"9.3.5.1 CD","versionType":"semver"},{"status":"affected","version":"9.4.0.0","lessThanOrEqual":"9.4.0.25 LTS","versionType":"semver"},{"status":"affected","version":"9.4.0.0","lessThanOrEqual":"9.4.5.1 CD","versionType":"semver"},{"status":"affected","version":"10.0.0.0"}],"cpes":["cpe:2.3:a:ibm:mq:9.1.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:mq:9.1.0.37:*:*:*:*:*:*:*","cpe:2.3:a:ibm:mq:9.2.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:mq:9.2.0.43:*:*:*:*:*:*:*","cpe:2.3:a:ibm:mq:9.3.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:mq:9.3.0.41:*:*:*:*:*:*:*","cpe:2.3:a:ibm:mq:9.3.5.1:*:*:*:*:*:*:*","cpe:2.3:a:ibm:mq:9.4.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:mq:9.4.0.25:*:*:*:*:*:*:*","cpe:2.3:a:ibm:mq:9.4.5.1:*:*:*:*:*:*:*","cpe:2.3:a:ibm:mq:10.0.0.0:*:*:*:*:*:*:*"]}],"descriptions":[{"lang":"en","value":"IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to execute arbitrary code on the application server due to improper validation of JNDI names in the Resource Adapter Installation Verification Test application.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to execute arbitrary code on the application server due to improper validation of JNDI names in the Resource Adapter Installation Verification Test application.</p>"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7284908","tags":["vendor-advisory","patch"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseSeverity":"HIGH","baseScore":7.5,"vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"}}],"solutions":[{"lang":"en","value":"This issue was addressed under Known Issue DT473753\n\n\n\nIBM MQ version 9.1 LTS\n\n\n\n Apply cumulative security update 9.1.0.38 https://www.ibm.com/support/pages/downloading-ibm-mq-91-lts \n\n\n\nIBM MQ version 9.2 LTS\n\n\n\n Apply cumulative security update 9.2.0.44 https://www.ibm.com/support/pages/downloading-ibm-mq-92-lts \n\n\n\nIBM MQ version 9.3 LTS\n\n\n\n Apply cumulative security update 9.3.0.42 https://www.ibm.com/support/pages/downloading-ibm-mq-93-lts \n\n\n\nIBM MQ version 9.4 LTS\n\n\n\n Apply cumulative security update https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts   9.4.0.26 https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts \n\n\n\nIBM MQ version 9.3 CD, 9.4 CD and 10.0.0.0\n\n\n\n Upgrade to IBM MQ version 10.0.0.5 https://www.ibm.com/support/pages/downloading-ibm-mq-100","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>This issue was addressed under Known Issue DT473753</p><p>IBM MQ version 9.1 LTS</p><p><a href=\"https://www.ibm.com/support/pages/downloading-ibm-mq-91-lts\" rel=\"noopener noreferrer nofollow\">Apply cumulative security update 9.1.0.38</a></p><p>IBM MQ version 9.2 LTS</p><p><a href=\"https://www.ibm.com/support/pages/downloading-ibm-mq-92-lts\" rel=\"noopener noreferrer nofollow\">Apply cumulative security update 9.2.0.44</a></p><p>IBM MQ version 9.3 LTS</p><p><a href=\"https://www.ibm.com/support/pages/downloading-ibm-mq-93-lts\" rel=\"noopener noreferrer nofollow\">Apply cumulative security update 9.3.0.42</a></p><p>IBM MQ version 9.4 LTS</p><p><a href=\"https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts\" rel=\"noopener noreferrer nofollow\">Apply cumulative security update</a><a href=\"https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts\" rel=\"noopener noreferrer nofollow\"> 9.4.0.26</a></p><p>IBM MQ version 9.3 CD, 9.4 CD and 10.0.0.0</p><p><a href=\"https://www.ibm.com/support/pages/downloading-ibm-mq-100\" rel=\"noopener noreferrer nofollow\">Upgrade to IBM MQ version 10.0.0.5</a></p>"}]}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-15T00:00:00+00:00","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3","id":"CVE-2026-12354"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-16T03:56:36.302Z"}}]}}