CVE-2025-23225
MEDIUMDescription
IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow an authenticated user to cause a denial of service due to the improper handling of invalid headers sent to the queue.
Is your site exposed to CVE-2025-23225?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| ibm | mq_appliance |
| ibm | mq_appliance |
| ibm | mq_appliance |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-23225? +
How severe is CVE-2025-23225? +
What products are affected by CVE-2025-23225? +
How do I check if I'm vulnerable to CVE-2025-23225? +
Related Vulnerabilities
The RegistrationMagic – User Registration Plugin with Custom Registration Forms plugin for WordPress is vulnerable to privilege escalation via account …
The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions …
GVCP dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 allows denial of service via packet injection …
In Session of AccountManagerService.java, there is a possible method to retain foreground service privileges due to incorrect handling of null …
AppleTalk and RELOAD Framing dissector crash in Wireshark 4.4.0 and 4.2.0 to 4.2.7 allows denial of service via packet injection …
Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Missing Values (CWE-230) vulnerability where an …