Impact
IBM MQ is vulnerable to an XML external entity injection attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. This is a CWE‑611 vulnerability. An attacker supplying a crafted XML document can cause the MQ broker to resolve external entities, enabling them to read arbitrary local files or cause memory exhaustion. The primary impact is data confidentiality loss and potential resource depletion, affecting the affected IBM MQ releases listed earlier.
Affected Systems
Affected vendors include IBM MQ. Vulnerable releases are IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0. Full version details are enumerated in the CVE data.
Risk and Exploitability
The CVSS score of 7.1 reflects moderate to high severity. The EPSS score is less than 1%, indicating a very low but non‑zero chance of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an external client submitting a crafted XML payload that triggers the XXE parser in the MQ broker. Successful exploitation requires the broker to accept XML input, which is common for data transfer jobs. Because the affected component is part of the public interface, remote attackers could attempt the exploit without privileged access.
OpenCVE Enrichment