Sensitive Information Exposure in IBM MQ Operator
CVE-2025-36005
What is CVE-2025-36005?
The IBM MQ Operator is at risk of sensitive information exposure due to improper certificate validation. This vulnerability allows a malicious user to potentially access sensitive information from another TLS session if they can connect to the same hostname and port through the proxy. This issue affects multiple versions of the IBM MQ Operator, underscoring the importance of proper certificate management and security protocols.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
MQ Operator 2.0.0 LTS <= 2.0.29 LTS
MQ Operator 3.0.0, 3.0.1, 3.1.0, 3.1.3, 3.4.0, 3.5.0, 3.5.1, 3.6.0 CD
MQ Operator 3.2.0 SC2 <= 3.2.13 SC2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved