Impact
IBM MQ versions 9.1.0.0 through 9.1.0.37, 9.2.0.0 through 9.2.0.43, 9.3.0.0 through 9.3.0.41, 9.3.0.0 through 9.3.5.1, 9.4.0.0 through 9.4.0.25, 9.4.0.0 through 9.4.5..0 process XML data without properly disabling external entities, exposing them to a remote attacker. The vulnerability is a classic XML external entity (XXE) flaw (CWE-611) that can lead to the exfiltration of confidential files or data and can also cause excessive memory consumption or denial of service if a malicious XML document is submitted.
Affected Systems
All IBM MQ products, including IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.4 LTS, and IBM MQ 10.0.0, are vulnerable in the versions listed above. The specific impacted versions are those with major releases from 9.1.0.0 to 9.4.5.1 and the initial release of 10.0.0.0.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.1, indicating a moderate to high risk. The EPSS score is 0.00385 (≈0.4%), showing a very low but non-zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. An attacker can remotely submit malicious XML, for example in application requests or messages passed through MQ, to trigger the XXE vulnerability. No known public exploit requires special prerequisites beyond having network access to the MQ environment that processes XML data.
OpenCVE Enrichment