Executive brief
IBM MQ's Managed File Transfer component processes XML messages from authenticated users. An attacker with valid credentials could exploit an XML external entity (XXE) vulnerability to read arbitrary files from the server or perform server-side request forgery attacks, potentially exposing sensitive configuration data or facilitating further attacks on internal systems.
Technical details
This is an XML external entity (XXE) injection vulnerability (CWE-611) in the Managed File Transfer agent's reply message processing. The vulnerable component fails to properly restrict XML external entity references, allowing an authenticated attacker to craft malicious XML payloads. Attack vector is network-based with low complexity; authentication is required as a precondition. Successful exploitation enables arbitrary file read and server-side request forgery (SSRF). IBM has released cumulative security updates for affected versions: 9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26, and 10.0.0.5.
Affected products
- IBM MQ 9.1.0.0 to 9.1.0.37 LTS, 9.2.0.0 to 9.2.0.43 LTS, 9.3.0.0 to 9.3.0.41 LTS, 9.3.0.0 to 9.3.5.1 CD, 9.4.0.0 to 9.4.0.25 LTS, 9.4.0.0 to 9.4.5.1 CD, 10.0.0.0
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched: Security updates available: 9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26, and 10.0.0.5