VYPR
Medium severity5.9NVD Advisory· Published Jul 24, 2025· Updated Jun 17, 2026

CVE-2025-36005

CVE-2025-36005

Description

IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, 3.6.0, and MQ Operator SC2 3.2.0 through 3.2.13 Internet Pass-Thru could allow a malicious user to obtain sensitive information from another TLS session connection by the proxy to the same hostname and port due to improper certificate validation.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • IBM/MQ Operatorcpe-rescue4 versions
    cpe:2.3:a:ibm:mq_operator:2.0.0:*:*:*:lts:*:*:*+ 3 more
    • cpe:2.3:a:ibm:mq_operator:2.0.0:*:*:*:lts:*:*:*range: 2.0.0 LTS
    • cpe:2.3:a:ibm:mq_operator:3.0.0:*:*:*:continuous_delivery:*:*:*range: 3.0.0, 3.0.1, 3.1.0, 3.1.3, 3.4.0, 3.5.0, 3.5.1, 3.6.0 CD
    • cpe:2.3:a:ibm:mq_operator:3.2.0:*:*:*:support_cycle_2:*:*:*range: 3.2.0 SC2
    • (no CPE)range: 2.0.0 - 2.0.29, 3.0.0 - 3.1.3, 3.3.0 - 3.6.0, 3.2.0 - 3.2.13

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.