No advisories yet.
Solution
This issue was addressed under Known Issue DT474594 IBM MQ version 9.1 LTS Apply cumulative security update 9.1.0.38 https://www.ibm.com/support/pages/downloading-ibm-mq-91-lts IBM MQ version 9.2 LTS Apply cumulative security update 9.2.0.44 https://www.ibm.com/support/pages/downloading-ibm-mq-92-lts IBM MQ version 9.3 LTS Apply cumulative security update 9.3.0.42 https://www.ibm.com/support/pages/downloading-ibm-mq-93-lts IBM MQ version 9.4 LTS Apply cumulative security update https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts 9.4.0.26 https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts IBM MQ version 9.3 CD, 9.4 CD and 10.0.0.0 Upgrade to IBM MQ version 10.0.0.5 https://www.ibm.com/support/pages/downloading-ibm-mq-100
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7284895 |
|
Mon, 14 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker with MFT publish authority to obtain sensitive information or cause a denial of service due to XML external entity injection in the mqweb MFT REST API. | |
| Title | IBM MQ Managed File Transfer REST API is vulnerable to XML external entity injection | |
| First Time appeared |
Ibm
Ibm mq |
|
| Weaknesses | CWE-611 | |
| CPEs | cpe:2.3:a:ibm:mq:10.0.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:mq:9.1.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:mq:9.1.0.37:*:*:*:*:*:*:* cpe:2.3:a:ibm:mq:9.2.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:mq:9.2.0.43:*:*:*:*:*:*:* cpe:2.3:a:ibm:mq:9.3.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:mq:9.3.0.41:*:*:*:*:*:*:* cpe:2.3:a:ibm:mq:9.3.5.1:*:*:*:*:*:*:* cpe:2.3:a:ibm:mq:9.4.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:mq:9.4.0.25:*:*:*:*:*:*:* cpe:2.3:a:ibm:mq:9.4.5.1:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm mq |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-09-14T21:10:43.931Z
Reserved: 2026-06-24T21:12:02.885Z
Link: CVE-2026-13265
No data.
Status : Received
Published: 2026-09-14T22:16:57.100
Modified: 2026-09-14T22:16:57.100
Link: CVE-2026-13265
No data.
OpenCVE Enrichment
No data.