IBM MQ LTS 9.1.0.0 through 9.1.0.29, 9.2.0.0 through 9.2.0.36, 9.3.0.0 through 9.3.0.30 and 9.4.0.0 through 9.4.0.12 and IBM MQ CD 9.3.0.0 through 9.3.5.1 and 9.4.0.0 through 9.4.3.0 Java and JMS stores a password in client configuration files when trace is enabled which can be read by a local user.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.ibm.com/support/pages/node/7243544 |
![]() ![]() |
History
Mon, 08 Sep 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sun, 07 Sep 2025 00:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | IBM MQ LTS 9.1.0.0 through 9.1.0.29, 9.2.0.0 through 9.2.0.36, 9.3.0.0 through 9.3.0.30 and 9.4.0.0 through 9.4.0.12 and IBM MQ CD 9.3.0.0 through 9.3.5.1 and 9.4.0.0 through 9.4.3.0 Java and JMS stores a password in client configuration files when trace is enabled which can be read by a local user. | |
Title | IBM MQ information disclosure | |
First Time appeared |
Ibm
Ibm mq |
|
Weaknesses | CWE-260 | |
CPEs | cpe:2.3:a:ibm:mq:9.1.0.0:*:*:*:lts:*:*:* cpe:2.3:a:ibm:mq:9.1.0.29:*:*:*:lts:*:*:* cpe:2.3:a:ibm:mq:9.2.0.0:*:*:*:lts:*:*:* cpe:2.3:a:ibm:mq:9.2.0.36:*:*:*:lts:*:*:* cpe:2.3:a:ibm:mq:9.3.0.0:*:*:*:continuous_delivery:*:*:* cpe:2.3:a:ibm:mq:9.3.0.0:*:*:*:lts:*:*:* cpe:2.3:a:ibm:mq:9.3.0.30:*:*:*:lts:*:*:* cpe:2.3:a:ibm:mq:9.3.5.1:*:*:*:continuous_delivery:*:*:* cpe:2.3:a:ibm:mq:9.4.0.0:*:*:*:continuous_delivery:*:*:* cpe:2.3:a:ibm:mq:9.4.0.0:*:*:*:lts:*:*:* cpe:2.3:a:ibm:mq:9.4.0.12:*:*:*:lts:*:*:* cpe:2.3:a:ibm:mq:9.4.3.0:*:*:*:continuous_delivery:*:*:* |
|
Vendors & Products |
Ibm
Ibm mq |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: ibm
Published: 2025-09-07T00:37:00.421Z
Updated: 2025-09-08T17:50:31.796Z
Reserved: 2025-04-15T21:16:16.297Z
Link: CVE-2025-36100

Updated: 2025-09-08T17:50:22.346Z

Status : Awaiting Analysis
Published: 2025-09-07T01:15:32.370
Modified: 2025-09-08T16:25:38.810
Link: CVE-2025-36100

No data.