Sensitive Information Exposure in IBM MQ Operator
CVE-2025-36005

5.9MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
24 July 2025

What is CVE-2025-36005?

The IBM MQ Operator is at risk of sensitive information exposure due to improper certificate validation. This vulnerability allows a malicious user to potentially access sensitive information from another TLS session if they can connect to the same hostname and port through the proxy. This issue affects multiple versions of the IBM MQ Operator, underscoring the importance of proper certificate management and security protocols.

Affected Version(s)

MQ Operator 2.0.0 LTS <= 2.0.29 LTS

MQ Operator 3.0.0, 3.0.1, 3.1.0, 3.1.3, 3.4.0, 3.5.0, 3.5.1, 3.6.0 CD

MQ Operator 3.2.0 SC2 <= 3.2.13 SC2

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.