VYPR
Unrated severityNVD Advisory· Published Jul 24, 2025· Updated Aug 17, 2025

IBM MQ Operator information disclosure

CVE-2025-36005

Description

IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, 3.6.0, and MQ Operator SC2 3.2.0 through 3.2.13 Internet Pass-Thru could allow a malicious user to obtain sensitive information from another TLS session connection by the proxy to the same hostname and port due to improper certificate validation.

Affected products

4
  • IBM/MQ Operatorv53 versions
    cpe:2.3:a:ibm:mq_operator:2.0.0:*:*:*:lts:*:*:*+ 2 more
    • cpe:2.3:a:ibm:mq_operator:2.0.0:*:*:*:lts:*:*:*range: 2.0.0 LTS
    • cpe:2.3:a:ibm:mq_operator:3.0.0:*:*:*:continuous_delivery:*:*:*range: 3.0.0, 3.0.1, 3.1.0, 3.1.3, 3.4.0, 3.5.0, 3.5.1, 3.6.0 CD
    • cpe:2.3:a:ibm:mq_operator:3.2.0:*:*:*:support_cycle_2:*:*:*range: 3.2.0 SC2
  • Range: LTS 2.0.0 through 2.0.29, CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, 3.6.0, SC2 3.2.0 through 3.2.13

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.