Impact
The vulnerability is an XML External Entity (XEE) injection flaw in the IBM MQ web Managed File Transfer REST API. An attacker who authenticates with MFT publish authority can provide a crafted XML payload that triggers the resolution of an external entity. This can lead the server to read arbitrary files or transmit sensitive configuration details, or it can exhaust system resources, resulting in a denial of service. The flaw is categorized as CWE‑611.
Affected Systems
IBM MQ 9.1 LTS versions 9.1.0.0 through 9.1.0.37, IBM MQ 9.2 LTS versions 9.2.0.0 through 9.2.0.43, IBM MQ 9.3 LTS versions 9.3.0.0 through 9.3.0.41 and 9.3.5.1 CD, IBM MQ 9.4 LTS versions 9.4.0.0 through 9.4.0.25 and 9.4.5.1 CD, and IBM MQ 10.0.0.0. Each of these releases includes a cumulative security update that addresses the flaw.
Risk and Exploitability
The vulnerability has a CVSS score of 6.8, indicating a moderate level of severity. Its EPSS score is reported as < 1%, indicating a very low likelihood of exploitation; the flaw is not listed in the CISA KEV catalog. Exploitation requires that the attacker obtain authenticated access with MFT publish authority, which limits the threat window but still represents a non‑negligible risk for organizations running the affected MQ versions.
OpenCVE Enrichment