CVE-2019-4239
Description
IBM MQ Advanced Cloud Pak (IBM Cloud Private 1.0.0 through 3.0.1) stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 159465.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
IBM MQ Advanced Cloud Pak stores user credentials in plaintext in container logs, exposing them to local users.
Vulnerability
IBM MQ Advanced Cloud Pak, when deployed on IBM Cloud Private versions 1.0.0 through 3.0.1 or on RedHat OpenShift versions 2.1.0 through 2.3.1, stores user credentials in plain text in container logs [1]. This occurs due to the application printing passwords directly into log output, which can be accessed by any local user on the system.
Exploitation
An attacker with local access to the system where the container logs are stored (or mirrored to an external logging service) can read the logs and extract plaintext credentials [1]. No authentication or user interaction is required, as the logs are generated automatically and accessible to local users.
Impact
Successful exploitation leads to disclosure of sensitive credentials, such as passwords, which can be used to gain unauthorized access to systems or escalate privileges. The confidentiality of user credentials is compromised, with no impact on integrity or availability [1].
Mitigation
As of the publication of the advisory, no fix or workaround has been provided by IBM [1]. Users should monitor for updates from IBM and consider restricting access to container logs as a temporary measure.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4- Range: >=1.0.0, <=3.0.1
- Range: >=1.0.0, <=3.0.1
- IBM/MQ Advanced Cloud Pak (IBM Cloud Private)v5Range: 1.0.0
- IBM/MQ Advanced Cloud Pak (IBM Cloud Private on RedHat OpenShift)v5Range: 1.0.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- exchange.xforce.ibmcloud.com/vulnerabilities/159465mitrevdb-entryx_refsource_XF
- www.ibm.com/support/docview.wssmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.