I
BM MQ LTS 9.1.0.0 through 9.1.0.29, 9.2.0.0 through 9.2.0.36, 9.3.0.0 through 9.3.0.30 and 9.4.0.0 through 9.4.0.12 and IBM MQ CD 9.3.0.0 through 9.3.5.1 and 9.4.0.0 through 9.4.3.0 Java and JMS stores a password in client configuration files when trace is enabled which can be read by a local user.
References
| Link | Resource |
|---|---|
| https://www.ibm.com/support/pages/node/7243544 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
19 Dec 2025, 15:01
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:ibm:mq:*:*:*:*:continuous_delivery:*:*:* cpe:2.3:a:ibm:mq:*:*:*:*:lts:*:*:* |
|
| First Time |
Ibm mq
Ibm |
|
| References | () https://www.ibm.com/support/pages/node/7243544 - Patch, Vendor Advisory |
08 Sep 2025, 16:25
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-09-07 01:15
Updated : 2025-12-19 15:01
NVD link : CVE-2025-36100
Mitre link : CVE-2025-36100
CVE.ORG link : CVE-2025-36100
JSON object : View
CWE
CWE-260
Password in Configuration File