IBM MQ 9.4 LTS
IBM MQ 9.4 LTS
Third-party support for the IBM MQ 9.4 LTS: 24/7 engineers manage issues, remediate vulnerabilities, and help you maintain compliance — independent of the vendor contract.
24/7 engineers own your IBM MQ 9.4 LTS incidents end to end.
Mitigation and patch-around guidance when the vendor no longer ships fixes.
Controls evidence and documentation that keep auditors satisfied.
Specifications
- product
- ibm-mq
- release
- 9.4
- product Label
- IBM MQ
- release Label
- IBM MQ 9.4 LTS
- codename
- lts
- latest Version
- release Date
- 2024-06-18
- maintained
- true
- source Url
- https://endoflife.date/ibm-mq
OEM vs. 3rd Party Support
See how third-party support compares to the vendor contract for IBM MQ 9.4 LTS — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.
| Feature | OEM Support | 3rd Party Support |
|---|---|---|
| Post-EOSL Support | ||
| Break/Fix Support | Until EOSL | |
| 24/7 Monitoring | ||
| Vulnerability Scanning & Remediation | ||
| Managed Operations | ||
| Procedure & Configuration Review | ||
| Compliance & Audit Documentation | Limited | |
| Discounted Migration to Other Platforms |
Why Choose 3rd Party Support for IBM MQ 9.4 LTS?
Vulnerability Remediation
Scanning, mitigation and patch-around guidance for IBM MQ 9.4 LTS when the vendor no longer ships fixes.
Compliance Maintenance
Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.
24/7 Expert Support
Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.
IBM MQ 9.4 LTS Support: Frequently Asked Questions
Is the IBM MQ 9.4 LTS still supported?
Yes. The IBM MQ 9.4 LTS is currently supported by IBM, and third-party support is available as an alternative — issue management, vulnerability remediation, and compliance help independent of the vendor contract.
How much does third-party support for the IBM MQ 9.4 LTS cost?
Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.
Known Vulnerabilities Affecting IBM MQ 9.4 LTS
8 published CVEs affect the IBM MQ 9.4 LTS, including 1 rated critical or high severity. Our 24/7 engineers help you assess exposure, prioritize fixes and apply available patches.
| CVE | Severity | CVSS | Published | Summary |
|---|---|---|---|---|
| CVE-2025-36128 | HIGH | 7.5 | Oct 16, 2025 | IBM MQ 9.1, 9.2, 9.3, 9.4 LTS and 9.3, 9.4 CD is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations. By conducting slowloris-type attacks, a remote attacker could exploit this vulnerability to cause a denial of service. |
| CVE-2024-52898 | MEDIUM | 6.2 | Jan 14, 2025 | IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a local user to obtain sensitive information when a detailed technical error message is returned. |
| CVE-2024-52897 | MEDIUM | 6.2 | Dec 19, 2024 | IBM MQ 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned. |
| CVE-2024-52896 | MEDIUM | 6.2 | Dec 19, 2024 | IBM MQ 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned. |
| CVE-2025-0985 | MEDIUM | 5.5 | Feb 28, 2025 | IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD stores potentially sensitive information in environment variables that could be obtained by a local user. |
| CVE-2024-54175 | MEDIUM | 5.5 | Feb 28, 2025 | IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow a local user to cause a denial of service due to an improper check for unusual or exceptional conditions. |
| CVE-2025-36100 | MEDIUM | 5.1 | Sep 7, 2025 | IBM MQ LTS 9.1.0.0 through 9.1.0.29, 9.2.0.0 through 9.2.0.36, 9.3.0.0 through 9.3.0.30 and 9.4.0.0 through 9.4.0.12 and IBM MQ CD 9.3.0.0 through 9.3.5.1 and 9.4.0.0 through 9.4.3.0 Java and JMS stores a password in client configuration files when trace is enabled which can be read by a local user. |
| CVE-2026-1713 | MEDIUM | 5.0 | Mar 3, 2026 | IBM MQ 9.1.0.0 through 9.1.0.33 LTS, 9.2.0.0 through 9.2.0.40 LTS, 9.3.0.0 through 9.3.0.36 LTS, 9.30.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.17 LTS, and 9.4.0.0 through 9.4.4.1 CD |