Sensitive Information Exposure in IBM MQ Operator
CVE-2025-36005
5.9MEDIUM
What is CVE-2025-36005?
The IBM MQ Operator is at risk of sensitive information exposure due to improper certificate validation. This vulnerability allows a malicious user to potentially access sensitive information from another TLS session if they can connect to the same hostname and port through the proxy. This issue affects multiple versions of the IBM MQ Operator, underscoring the importance of proper certificate management and security protocols.
Affected Version(s)
MQ Operator 2.0.0 LTS <= 2.0.29 LTS
MQ Operator 3.0.0, 3.0.1, 3.1.0, 3.1.3, 3.4.0, 3.5.0, 3.5.1, 3.6.0 CD
MQ Operator 3.2.0 SC2 <= 3.2.13 SC2
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved