Security Bulletin
Summary
IBM MQ Explorer is vulnerable to an XML External Entity Injection (XXE) attack due to improper XML validation in the import Wizard.
Vulnerability Details
CVEID: CVE-2022-22489
DESCRIPTION: IBM MQ is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
CVSS Base score: 8.2
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/226339 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L)
Affected Products and Versions
The following installable MQ components are affected by the vulnerability:
• IBM MQ Explorer
If you are running any of these listed components, please apply the remediation/fixes as described below. For more information on the definitions of components used in this list see https://www.ibm.com/support/pages/installable-component-names-used-ibm-mq-security-bulletins
Affected Product(s) | Version(s) |
IBM MQ | 9.1 LTS |
IBM MQ | 9.0 LTS |
IBM MQ | 8.0 |
IBM MQ | 9.2 CD |
IBM MQ | 9.1 CD |
IBM MQ | 9.2 LTS |
Remediation/Fixes
This issue was resolved under APAR IT39183
IBM MQ Version 8
IBM MQ Version 9.0
IBM MQ Version 9.1 LTS
IBM MQ Version 9.2 LTS
IBM MQ Version 9.1 CD and Version 9.2 CD
Workarounds and Mitigations
None
Get Notified about Future Security Bulletins
References
Acknowledgement
Change History
19 Jan 2023: Updated information to indicate MQ components affected
17 Aug 2022: Initial Publication
*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.
Disclaimer
Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.
Document Location
Worldwide
Was this topic helpful?
Document Information
Modified date:
19 January 2023
UID
ibm16613021