MEDIUM🇵🇱 Wersja polska

CVE-2025-36041

CVSS 4.7v3.1pub. 2025-06-15upd. 2025-08-22

IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1 through 3.5.3, and MQ Operator SC2 3.2.0 through 3.2.12 Native HA CRR could be configured with a private key and chain other than the intended key which could disclose sensitive information or allow the attacker to perform unauthorized actions.

CVSS Vector
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:H/A:N
  • IBM Mq Operator

    APP
    Ibm
    3.0.03.0.13.3.03.4.03.4.13.5.03.5.1 – 3.5.32.0.0 – 2.0.292.2.0 – 2.2.22.3.0 – 2.3.32.4.0 – 2.4.83.1.0 – 3.1.33.2.0 – 3.2.12
  • IBM Supplied Mq Advanced Container Images

    APP
    Ibm
    9.2.0.19.2.0.29.2.0.49.2.0.59.2.0.69.2.3.09.2.4.09.2.5.09.3.0.09.3.0.19.3.0.109.3.0.119.3.0.159.3.0.169.3.0.17+ 29 more
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-40681HIGH7.5same product

IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow an authenticated user in a specifica...

CVE-2024-39742HIGH8.1same product

IBM MQ Operator 3.2.2 and IBM MQ Operator 2.0.24 could allow a user to bypass authentication under certain con...

CVE-2025-36005MEDIUM5.9same product

IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4....

CVE-2025-33013MEDIUM6.2same product

IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4....

CVE-2025-27365MEDIUM6.5same product

IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4....