CVE-2025-36041

IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1 through 3.5.3, and MQ Operator SC2 3.2.0 through 3.2.12 Native HA CRR could be configured with a private key and chain other than the intended key which could disclose sensitive information or allow the attacker to perform unauthorized actions.
Configurations

No configuration.

History

16 Jun 2025, 12:32

Type Values Removed Values Added
Summary
  • (es) IBM MQ Operator LTS 2.0.0 a 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 a 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1 a 3.5.3 y MQ Operator SC2 3.2.0 a 3.2.12 Native HA CRR podrían configurarse con una clave privada y una cadena distinta a la clave prevista, lo que podría revelar información confidencial o permitir que el atacante realice acciones no autorizadas.

15 Jun 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-15 13:15

Updated : 2025-06-16 12:32


NVD link : CVE-2025-36041

Mitre link : CVE-2025-36041

CVE.ORG link : CVE-2025-36041


JSON object : View

Products Affected

No product.

CWE
CWE-295

Improper Certificate Validation