CVE-2025-36100

I

BM MQ LTS 9.1.0.0 through 9.1.0.29, 9.2.0.0 through 9.2.0.36, 9.3.0.0 through 9.3.0.30 and 9.4.0.0 through 9.4.0.12 and IBM MQ CD 9.3.0.0 through 9.3.5.1 and 9.4.0.0 through 9.4.3.0  Java and JMS stores a password in client configuration files when trace is enabled which can be read by a local user.

References
Link Resource
https://www.ibm.com/support/pages/node/7243544 Patch Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:mq:*:*:*:*:lts:*:*:*
cpe:2.3:a:ibm:mq:*:*:*:*:lts:*:*:*
cpe:2.3:a:ibm:mq:*:*:*:*:lts:*:*:*
cpe:2.3:a:ibm:mq:*:*:*:*:continuous_delivery:*:*:*
cpe:2.3:a:ibm:mq:*:*:*:*:lts:*:*:*
cpe:2.3:a:ibm:mq:*:*:*:*:continuous_delivery:*:*:*

History

19 Dec 2025, 15:01

Type Values Removed Values Added
CPE cpe:2.3:a:ibm:mq:*:*:*:*:continuous_delivery:*:*:*
cpe:2.3:a:ibm:mq:*:*:*:*:lts:*:*:*
First Time Ibm mq
Ibm
References () https://www.ibm.com/support/pages/node/7243544 - () https://www.ibm.com/support/pages/node/7243544 - Patch, Vendor Advisory

08 Sep 2025, 16:25

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-07 01:15

Updated : 2025-12-19 15:01


NVD link : CVE-2025-36100

Mitre link : CVE-2025-36100

CVE.ORG link : CVE-2025-36100


JSON object : View

Products Affected
CWE
CWE-260

Password in Configuration File