VYPR
Unrated severityNVD Advisory· Published Jan 27, 2025· Updated Feb 18, 2025

IBM MQ Operator information disclosure

CVE-2024-27256

Description

IBM MQ Container 3.0.0, 3.0.1, 3.1.0 through 3.1.3 CD, 2.0.0 LTS through 2.0.22 LTS and 2.4.0 through 2.4.8, 2.3.0 through 2.3.3, 2.2.0 through 2.2.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

Affected products

2
  • cpe:2.3:a:ibm:mq_operator:3.0.0:*:*:*:continuous_delivery:*:*:*
    Range: 2.4.0
  • Range: >=3.0.0 <=3.1.3 CD, >=2.0.0 LTS <=2.0.22 LTS, >=2.4.0 <=2.4.8, >=2.3.0 <=2.3.3, >=2.2.0 <=2.2.2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.