First published: Thu Aug 18 2022(Updated: )
IBM MQ 8.0, (9.0, 9.1, 9.2 LTS), and (9.1 and 9.2 CD) are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 226339.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM MQ | =8.0.0.0 | |
IBM MQ | =9.0.0.0 | |
IBM MQ | =9.1.0 | |
IBM MQ | =9.1.0.0 | |
IBM MQ | =9.2.0 | |
IBM MQ | =9.2.0 | |
Linux Linux kernel | ||
Microsoft Windows | ||
<=9.1 LTS | ||
<=9.0 LTS | ||
<=8.0 | ||
<=9.2 CD | ||
<=9.1 CD | ||
<=9.2 LTS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-22489 is an XML External Entity Injection (XXE) vulnerability in IBM MQ.
The vulnerability occurs when processing XML data in IBM MQ, allowing remote attackers to perform an XXE attack.
The severity of CVE-2022-22489 is critical with a CVSS score of 9.1.
IBM MQ versions 8.0, 9.0, 9.1, and 9.2 LTS, as well as 9.1 and 9.2 CD, are affected by this vulnerability.
Attackers can exploit this vulnerability to expose sensitive information or consume memory resources.