Impact
IBM MQ clients that process reply messages are vulnerable to XML external entity injection, which allows an attacker with authenticated access to the Managed File Transfer service to read arbitrary files on the server or to trigger server‑side requests to arbitrary URLs, thereby compromising confidentiality and potentially enabling further lateral movement.
Affected Systems
The vulnerability affects IBM MQ versions 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS and 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS and 9.4.5.1 CD, as well as version 10.0.0.0 of the Managed File Transfer component. These releases are listed under the IBM MQ product line.
Risk and Exploitability
The CVSS base score of 7.1 indicates a high‑severity vulnerability. The EPSS score is 0.251%, indicating a very low probability of exploitation, but the absence of a KEV listing suggests no widely publicized exploitation at this time. Based on the description, the attack vector is likely internal or network‑based, requiring authenticated access to the MFT server; an attacker would submit a crafted XML payload that causes the server to resolve external entity references.
OpenCVE Enrichment