IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 Managed File Transfer could allow an authenticated attacker to read arbitrary files or perform server-side request forgery due to XML external entity injection in reply message processing.
References
| Link | Resource |
|---|---|
| https://www.ibm.com/support/pages/node/7284897 |
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-14 21:17
Updated : 2026-09-15 19:17
NVD link : CVE-2026-13275
Mitre link : CVE-2026-13275
CVE.ORG link : CVE-2026-13275
JSON object : View
Products Affected
No product.
CWE
CWE-611
Improper Restriction of XML External Entity Reference
