CVE-2025-36100
EUVD-2025-2709207.09.2025, 01:15
IBM MQ LTS 9.1.0.0 through 9.1.0.29, 9.2.0.0 through 9.2.0.36, 9.3.0.0 through 9.3.0.30 and 9.4.0.0 through 9.4.0.12 and IBM MQ CD 9.3.0.0 through 9.3.5.1 and 9.4.0.0 through 9.4.3.0 Java and JMS stores a password in client configuration files when trace is enabled which can be read by a local user.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| ibm | mq | 9.1.0.0 ≤ 𝑥 < 9.1.0.31 |
| ibm | mq | 9.2.0.0 ≤ 𝑥 < 9.2.0.37 |
| ibm | mq | 9.3.0.0 ≤ 𝑥 < 9.3.0.31 |
| ibm | mq | 9.3.0.0 ≤ 𝑥 ≤ 9.3.5.1 |
| ibm | mq | 9.4.0.0 ≤ 𝑥 < 9.4.0.15 |
| ibm | mq | 9.4.0.0 ≤ 𝑥 < 9.4.3.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration