MEDIUM🇵🇱 Wersja polska

CVE-2025-33013

CVSS 6.2v3.1pub. 2025-07-24upd. 2025-08-22

IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, 3.6.0, and MQ Operator SC2 3.2.0 through 3.2.13 Container could disclose sensitive information to a local user due to improper clearing of heap memory before release.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • IBM Mq Operator

    APP
    Ibm
    3.3.03.4.03.4.13.5.02.0.0 – 2.0.293.2.0 – 3.2.133.5.1 – 3.6.0
  • IBM Supplied Mq Advanced Container Images

    APP
    Ibm
    9.3.0.09.3.0.19.3.0.109.3.0.119.3.0.159.3.0.169.3.0.179.3.0.209.3.0.219.3.0.259.3.0.39.3.0.49.3.0.59.3.0.69.4.0.0+ 10 more
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Container
CWE
References

Related vulnerabilities

CVE-2024-40681HIGH7.5same product

IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow an authenticated user in a specifica...

CVE-2024-39742HIGH8.1same product

IBM MQ Operator 3.2.2 and IBM MQ Operator 2.0.24 could allow a user to bypass authentication under certain con...

CVE-2025-36005MEDIUM5.9same product

IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4....

CVE-2025-36041MEDIUM4.7same product

IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4....

CVE-2025-27365MEDIUM6.5same product

IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4....