Executive brief
IBM MQ is a message-oriented middleware platform used across enterprises to reliably route and queue data between applications. The Managed File Transfer monitor component contains an XML external entity (XXE) injection vulnerability that allows authenticated attackers to extract sensitive information or exhaust system memory. This could compromise data confidentiality and cause service disruption in critical integration workflows.
Technical details
IBM MQ's Managed File Transfer monitor result parser fails to properly restrict XML external entity (XXE) references when processing XML input (CWE-611). This is an XXE vulnerability requiring authenticated network access; an attacker must have valid MQ credentials and network connectivity to the vulnerable component. Successful exploitation allows disclosure of sensitive files on the server or denial-of-service via XML bombs that consume unbounded memory. The vulnerability affects multiple versions across 9.1 LTS through 10.0.0.0. Patches are available: 9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26, and 10.0.0.5.
Affected products
- IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, 10.0.0.0
Timeline
- 2026-09-14: disclosed: IBM security bulletin published
- 2026-09-14: patched: Patches released: 9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26, 10.0.0.5