QID 378551

Date Published: 2023-06-27

QID 378551: IBM MQ Explorer Extensible Markup Language (XML) External Entity Injection (XXE) Vulnerability (6613021)

BM MQ is a message oriented middleware that allows independent and non-concurrent applications on a distributed system to communicate with each other.

IBM MQ Explorer is vulnerable to an XML External Entity Injection (XXE) attack.

Affected Version:
IBM MQ 8.0, 9.0, 9.1, 9.2

QID Detection Logic: (Authenticated)
Operating System: Windows
It checks for vulnerable IBM MQ versions.

Operating System: Linux
The QID runs the command "/opt/mqm/bin/dspmqver -v | grep -A3 '^Name'" and "/usr/mqm/bin/dspmqver -v | grep -A3 '^Name'" (for AIX only) to see if the system is running a vulnerable version of IBM MQ or not.

A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.

  • CVSS V3 rated as Critical - 9.1 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Please refer to advisory IBM MQ 6613021 for further information.

    Vendor References

    CVEs related to QID 378551

    Software Advisories
    Advisory ID Software Component Link
    6613021 URL Logo www.ibm.com/support/pages/node/6613021