Executive brief
IBM MQ is a message-oriented middleware platform used by enterprises to reliably exchange data across applications and systems. The Managed File Transfer component contains an XML parsing vulnerability that allows authenticated remote attackers to extract sensitive information or trigger denial-of-service conditions by crafting malicious XML payloads. This could expose business-critical data or disrupt file transfer operations.
Technical details
IBM MQ Managed File Transfer contains an XML external entity (XXE) injection vulnerability in its template parser due to improper restriction of XML external entity references (CWE-611). An attacker with valid credentials can send a specially crafted XML document to trigger entity expansion attacks, enabling information disclosure (reading arbitrary files or environment variables) or resource exhaustion (billion laughs/XML bomb attacks). The vulnerability requires prior authentication (PR:L) and network access (AV:N), but no user interaction. Patches are available for all supported versions via cumulative security updates.
Affected products
- IBM MQ 9.1.0.0 to 9.1.0.37 LTS, 9.2.0.0 to 9.2.0.43 LTS, 9.3.0.0 to 9.3.0.41 LTS, 9.3.0.0 to 9.3.5.1 CD, 9.4.0.0 to 9.4.0.25 LTS, 9.4.0.0 to 9.4.5.1 CD, 10.0.0.0
Timeline
- 2026-09-14: disclosed: Initial publication of IBM security bulletin
- 2026-09-14: patched: Patches available: MQ 9.1 LTS CSU 9.1.0.38, 9.2 LTS CSU 9.2.0.44, 9.3 LTS CSU 9.3.0.42, 9.4 LTS CSU 9.4.0.26, and upgrade to MQ 10.0.0.5 for CD/10.0.0.0