CVE-2026-13265
6.8
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H
Summary
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker with MFT publish authority to obtain sensitive information or cause a denial of service due to XML external entity injection in the mqweb MFT REST API.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| IBM | MQ | 9.1.0.0 <= 9.1.0.37 LTS | affected |
| IBM | MQ | 9.2.0.0 <= 9.2.0.43 LTS | affected |
| IBM | MQ | 9.3.0.0 <= 9.3.0.41 LTS | affected |
| IBM | MQ | 9.3.0.0 <= 9.3.5.1 CD | affected |
| IBM | MQ | 9.4.0.0 <= 9.4.0.25 LTS | affected |
| IBM | MQ | 9.4.0.0 <= 9.4.5.1 CD | affected |
| IBM | MQ | 10.0.0.0 | affected |
Weaknesses
- CWE-611: CWE-611 Improper Restriction of XML External Entity Reference
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.