Home

Description

IBM MQ Container when used with the IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, and MQ Operator SC2 3.2.0 through 3.2.10 and configured with Cloud Pak for Integration Keycloak could disclose sensitive information to a privileged user.

PUBLISHED Reserved 2025-02-15 | Published 2025-05-01 | Updated 2025-08-28 | Assigner ibm




MEDIUM: 6.0CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

Problem types

CWE-214 Invocation of Process Using Visible Sensitive Information

Product status

Default status
unaffected

2.0.0 LTS (semver)
affected

3.0.0, 3.0.1, 3.1.0, 3.1.3, 3.4.0, 3.5.0, 3.5.1 CD
affected

3.2.0 SC2 (semver)
affected

References

www.ibm.com/support/pages/node/7232272 vendor-advisory patch

cve.org (CVE-2025-1333)

nvd.nist.gov (CVE-2025-1333)

Download JSON