Home
MEDIUM: 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:NDefault status
unaffected
2.0.0 LTS (semver)
affected
3.0.0, 3.0.1, 3.1.0, 3.1.3, 3.4.0, 3.5.0, 3.5.1 CD
affected
3.2.0 SC2 (semver)
affected
Description
IBM MQ Container when used with the IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, and MQ Operator SC2 3.2.0 through 3.2.10 and configured with Cloud Pak for Integration Keycloak could disclose sensitive information to a privileged user.
Problem types
CWE-214 Invocation of Process Using Visible Sensitive Information
Product status
2.0.0 LTS (semver)
3.0.0, 3.0.1, 3.1.0, 3.1.3, 3.4.0, 3.5.0, 3.5.1 CD
3.2.0 SC2 (semver)
References
www.ibm.com/support/pages/node/7232272