IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 Classes for Java could allow an authenticated attacker to obtain sensitive information or cause a denial of service due to XML external entity injection in MQRFH2 header processing.
References
| Link | Resource |
|---|---|
| https://www.ibm.com/support/pages/node/7284939 |
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-15 18:17
Updated : 2026-09-15 18:17
NVD link : CVE-2026-12666
Mitre link : CVE-2026-12666
CVE.ORG link : CVE-2026-12666
JSON object : View
Products Affected
No product.
CWE
CWE-611
Improper Restriction of XML External Entity Reference
