CyberRota Analysis
AI-GeneratedIBM MQ versions 9.1.0.0 through 10.0.0.0 are vulnerable to XML external entity injection, enabling authenticated attackers to read arbitrary files or execute server-side request forgery. This vulnerability poses a significant risk to data confidentiality and integrity, making it critical for organizations using affected versions to prioritize patching. Users of IBM MQ, particularly those handling sensitive data or operating in regulated environments, should take immediate action to mitigate this risk.
Original NVD Description
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 Managed File Transfer could allow an authenticated attacker to read arbitrary files or perform server-side request forgery due to XML external entity injection in reply message processing.