Unrated severityNVD Advisory· Published Jan 27, 2025· Updated Feb 18, 2025
IBM MQ Operator information disclosure
CVE-2024-27256
Description
IBM MQ Container 3.0.0, 3.0.1, 3.1.0 through 3.1.3 CD, 2.0.0 LTS through 2.0.22 LTS and 2.4.0 through 2.4.8, 2.3.0 through 2.3.3, 2.2.0 through 2.2.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Affected products
2- cpe:2.3:a:ibm:mq_operator:3.0.0:*:*:*:continuous_delivery:*:*:*Range: 2.4.0
- Range: >=3.0.0 <=3.1.3 CD, >=2.0.0 LTS <=2.0.22 LTS, >=2.4.0 <=2.4.8, >=2.3.0 <=2.3.3, >=2.2.0 <=2.2.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.