CyberRota Analysis
AI-GeneratedIBM MQ versions 9.1 through 10.0 are vulnerable to an issue that allows authenticated attackers to read sensitive files from a .NET client or potentially induce a limited denial of service through improper XML external entity handling in RFH2 folder parsing. Organizations using these versions should prioritize patching to mitigate the risk of data exposure and service disruption. This vulnerability is particularly critical for environments where IBM MQ is integral to application messaging and data transfer.
Original NVD Description
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to read files from a vulnerable .NET client or cause limited denial of service due to improper handling of XML external entities in RFH2 folder parsing.