Sensitive Information Exposure in IBM MQ Operator
CVE-2025-36005
5.9MEDIUM
What is CVE-2025-36005?
The IBM MQ Operator is at risk of sensitive information exposure due to improper certificate validation. This vulnerability allows a malicious user to potentially access sensitive information from another TLS session if they can connect to the same hostname and port through the proxy. This issue affects multiple versions of the IBM MQ Operator, underscoring the importance of proper certificate management and security protocols.
Affected Version(s)
MQ Operator 2.0.0 LTS <= 2.0.29 LTS
MQ Operator 3.0.0, 3.0.1, 3.1.0, 3.1.3, 3.4.0, 3.5.0, 3.5.1, 3.6.0 CD
MQ Operator 3.2.0 SC2 <= 3.2.13 SC2