Unrated severityNVD Advisory· Published Jul 24, 2025· Updated Aug 17, 2025
IBM MQ Operator information disclosure
CVE-2025-36005
Description
IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, 3.6.0, and MQ Operator SC2 3.2.0 through 3.2.13 Internet Pass-Thru could allow a malicious user to obtain sensitive information from another TLS session connection by the proxy to the same hostname and port due to improper certificate validation.
Affected products
4- IBM/MQ Operatorv53 versions
cpe:2.3:a:ibm:mq_operator:2.0.0:*:*:*:lts:*:*:*+ 2 more
- cpe:2.3:a:ibm:mq_operator:2.0.0:*:*:*:lts:*:*:*range: 2.0.0 LTS
- cpe:2.3:a:ibm:mq_operator:3.0.0:*:*:*:continuous_delivery:*:*:*range: 3.0.0, 3.0.1, 3.1.0, 3.1.3, 3.4.0, 3.5.0, 3.5.1, 3.6.0 CD
- cpe:2.3:a:ibm:mq_operator:3.2.0:*:*:*:support_cycle_2:*:*:*range: 3.2.0 SC2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.ibm.com/support/pages/node/7240431mitrevendor-advisorypatch
News mentions
0No linked articles in our index yet.