← Back

CVE-2025-36041

nvd nist
Published: Jun 15, 2025Modified: Aug 22, 2025

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1 through 3.5.3, and MQ Operator SC2 3.2.0 through 3.2.12 Native HA CRR could be configured with a private key and chain other than the intended key which could disclose sensitive information or allow the attacker to perform unauthorized actions.

Affected (129)

2 products
Mq Operator
Configuration A
129 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
From 2.2.0 to 2.2.2
From 2.3.0 to 2.3.3
From 2.4.0 to 2.4.8
From 3.1.0 to 3.1.3
From 3.5.1 to 3.5.3
From 2.0.0 to 2.0.29
From 3.2.0 to 3.2.12
Version 3.0.0
Version 3.0.1
Version 3.3.0
Version 3.4.0
Version 3.4.1
Version 3.5.0
Ibm
Version 9.2.0.1 r1-eus
Version 9.2.0.1 r1-eus
Version 9.2.0.2 r1-eus
Version 9.2.0.2 r1-eus
Version 9.2.0.2 r2-eus
Version 9.2.0.2 r2-eus
Version 9.2.0.4 r1-eus
Version 9.2.0.4 r1-eus
Version 9.2.0.5 r1-eus
Version 9.2.0.5 r1-eus
Version 9.2.0.5 r2-eus
Version 9.2.0.5 r2-eus
Version 9.2.0.5 r3-eus
Version 9.2.0.5 r3-eus
Version 9.2.0.6 r1-eus
Version 9.2.0.6 r1-eus
Version 9.2.0.6 r2-eus
Version 9.2.0.6 r2-eus
Version 9.2.0.6 r3-eus
Version 9.2.0.6 r3-eus
Version 9.2.3.0 r1
Version 9.2.3.0 r1
Version 9.2.4.0 r1
Version 9.2.4.0 r1
Version 9.2.5.0 r1
Version 9.2.5.0 r1
Version 9.2.5.0 r2
Version 9.2.5.0 r2
Version 9.2.5.0 r3
Version 9.2.5.0 r3
Version 9.3.0.0 r1
Version 9.3.0.0 r1
Version 9.3.0.0 r2
Version 9.3.0.0 r2
Version 9.3.0.0 r3
Version 9.3.0.0 r3
Version 9.3.0.10 r1
Version 9.3.0.10 r2
Version 9.3.0.11 r1
Version 9.3.0.11 r2
Version 9.3.0.15 r1
Version 9.3.0.16 r1
Version 9.3.0.16 r2
Version 9.3.0.17 r1
Version 9.3.0.17 r2
Version 9.3.0.17 r3
Version 9.3.0.1 r1
Version 9.3.0.1 r1
Version 9.3.0.1 r2
Version 9.3.0.1 r2
Version 9.3.0.1 r3
Version 9.3.0.1 r3
Version 9.3.0.1 r4
Version 9.3.0.1 r4
Version 9.3.0.20 r1
Version 9.3.0.20 r2
Version 9.3.0.21 r1
Version 9.3.0.21 r2
Version 9.3.0.21 r3
Version 9.3.0.25 r1
Version 9.3.0.3 r1
Version 9.3.0.3 r1
Version 9.3.0.4 r1
Version 9.3.0.4 r1
Version 9.3.0.4 r2
Version 9.3.0.4 r2
Version 9.3.0.5 r1
Version 9.3.0.5 r1
Version 9.3.0.5 r2
Version 9.3.0.5 r2
Version 9.3.0.5 r3
Version 9.3.0.5 r3
Version 9.3.0.6 r1
Version 9.3.0.6 r1
Version 9.3.1.0 r1
Version 9.3.1.0 r2
Version 9.3.1.0 r3
Version 9.3.1.1 r1
Version 9.3.2.0 r1
Version 9.3.2.0 r2
Version 9.3.2.1 r1
Version 9.3.2.1 r2
Version 9.3.3.0 r1
Version 9.3.3.0 r2
Version 9.3.3.1 r1
Version 9.3.3.1 r2
Version 9.3.3.2 r1
Version 9.3.3.2 r2
Version 9.3.3.2 r3
Version 9.3.3.3 r1
Version 9.3.3.3 r2
Version 9.3.4.0 r1
Version 9.3.4.1 r1
Version 9.3.5.0 r1
Version 9.3.5.0 r2
Version 9.3.5.1 r1
Version 9.3.5.1 r2
Version 9.4.0.0 r1
Version 9.4.0.0 r2
Version 9.4.0.0 r3
Version 9.4.0.10 r1
Version 9.4.0.10 r2
Version 9.4.0.11 r1
Version 9.4.0.11 r2
Version 9.4.0.5 r1
Version 9.4.0.5 r2
Version 9.4.0.6 r1
Version 9.4.0.6 r2
Version 9.4.0.7 r1
Version 9.4.1.0 r1
Version 9.4.1.0 r2
Version 9.4.1.1 r1
Version 9.4.2.0 r1
Version 9.4.2.0 r2
Version 9.4.2.1 r1
Version 9.4.2.1 r2

References (1)

Source: psirt@us.ibm.com
Vendor Advisory

Timeline

No history available yet.