Home

Description

IBM MQ LTS 9.1.0.0 through 9.1.0.29, 9.2.0.0 through 9.2.0.36, 9.3.0.0 through 9.3.0.30 and 9.4.0.0 through 9.4.0.12 and IBM MQ CD 9.3.0.0 through 9.3.5.1 and 9.4.0.0 through 9.4.3.0  Java and JMS stores a password in client configuration files when trace is enabled which can be read by a local user.

PUBLISHED Reserved 2025-04-15 | Published 2025-09-07 | Updated 2025-10-09 | Assigner ibm




MEDIUM: 5.1CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Problem types

CWE-260 Password in Configuration File

Product status

Default status
unaffected

9.1.0.0 (semver)
affected

9.2.0.0 (semver)
affected

9.3.0.0 (semver)
affected

9.4.0.0 (semver)
affected

Default status
unaffected

9.3.0.0 (semver)
affected

9.4.0.0 (semver)
affected

References

www.ibm.com/support/pages/node/7243544 vendor-advisory patch

cve.org (CVE-2025-36100)

nvd.nist.gov (CVE-2025-36100)

Download JSON