CVE-2023-47745

EUVD-2023-51843
IBM MQ Operator 2.0.0 LTS, 2.0.18 LTS, 3.0.0 CD, 3.0.1 CD, 2.4.0 through 2.4.7, 2.3.0 through 2.3.3, 2.2.0 through 2.2.2, and 2.3.0 through 2.3.3 stores or transmits user credentials in plain clear text which can be read by a local user using a trace command.  IBM X-Force ID:  272638.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.2 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
ibmCNA
6.2 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 1%
Affected Products (NVD)
VendorProductVersion
ibmmq_operator
2.2.0 ≤
𝑥
≤ 2.2.2
ibmmq_operator
2.3.0 ≤
𝑥
≤ 2.3.3
ibmmq_operator
2.4.0 ≤
𝑥
≤ 2.4.7
ibmmq_operator
2.0.0
ibmmq_operator
2.0.18
ibmmq_operator
3.0.0
ibmmq_operator
3.0.1
𝑥
= Vulnerable software versions