IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker with MFT publish authority to obtain sensitive information or cause a denial of service due to XML external entity injection in the mqweb MFT REST API.
References
| Link | Resource |
|---|---|
| https://www.ibm.com/support/pages/node/7284895 |
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-14 22:16
Updated : 2026-09-15 18:17
NVD link : CVE-2026-13265
Mitre link : CVE-2026-13265
CVE.ORG link : CVE-2026-13265
JSON object : View
Products Affected
No product.
CWE
CWE-611
Improper Restriction of XML External Entity Reference
