Impact
The vulnerability is an XML external entity injection flaw in IBM MQ’s .NET client. When a client processes a crafted XML document, the parser may resolve external entities, enabling an attacker to read files stored on the client machine or to trigger a limited denial‑of‑service condition. The weakness is identified as CWE‑611.
Affected Systems
The flaw affects IBM MQ .NET clients in versions 9.1.0.0 through 9.1.0.37, 9.2.0.0 through 9.2.0.43, 9.3.0.0 through 9.3.0.41, 9.3.0.0 through 9.3.5.1 in the CD distribution, 9.4.0.0 through 9.4.0.25, 9.4.0.0 through 9.4.5.1 in the CD distribution, and 10.0.0.0. IBM publishes cumulative security updates that address this issue: 9.1.0.38 for 9.1 LTS, 9.2.0.44 for 9.2 LTS, 9.3.0.42 for 9.3 LTS and the 9.3 CD releases, 9.4.0.26 for 9.4 LTS and the 9.4 CD releases, and version 10.0.0.5 for the 10.0.0.0 release.
Risk and Exploitability
With a CVSS score of 7.1 the flaw is considered high severity. The EPSS score of less than 1% indicates a very low probability of exploitation and the vulnerability is not listed in CISA KEV, suggesting no widespread exploitation to date. The likely attack path involves an authenticated .NET client that receives or sends a malicious XML document; the client's XML parser then resolves external entities to access files on the client machine or to cause a limited denial of service. Based on the description, it is inferred that an attacker must first authenticate to the MQ system and then supply a crafted XML payload to the client for the flaw to be triggered.
OpenCVE Enrichment