Impact
IBM MQ processes MQRFH2 headers that contain XML. In affected versions the XML parser does not properly restrict external entity resolution, allowing an authenticated attacker to embed external entity references and cause the server to dereference local files or network resources. This can lead to sensitive information disclosure or trigger a denial‑of‑service if the input is malformed.
Affected Systems
Affected products are IBM MQ across multiple LTS and CDN releases. The vulnerability exists in IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CDN, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CDN, and in the 10.0.0.0 Java classes. IBM recommends applying the cumulative security update appropriate for each version (for example 9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26, or 10.0.0.5).
Risk and Exploitability
The CVSS score of 8.1 indicates high impact, and the EPSS score is 0.00264, indicating a very low exploitation probability, but the vulnerability is not listed in the CISA KEV catalog. Because the flaw requires authentication with the message broker, the attack vector is likely over an authenticated network session to IBM MQ. The risk remains high for environments that expose MQ services to internal attackers or misconfigured clients, and remediation through patching is imperative.
OpenCVE Enrichment