IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1 through 3.5.3, and MQ Operator SC2 3.2.0 through 3.2.12 Native HA CRR could be configured with a private key and chain other than the intended key which could disclose sensitive information or allow the attacker to perform unauthorized actions.
References
| Link | Resource |
|---|---|
| https://www.ibm.com/support/pages/node/7236608 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2025-06-15 13:15
Updated : 2025-08-22 18:33
NVD link : CVE-2025-36041
Mitre link : CVE-2025-36041
CVE.ORG link : CVE-2025-36041
JSON object : View
Products Affected
ibm
- supplied_mq_advanced_container_images
- mq_operator
CWE
CWE-295
Improper Certificate Validation
