6.2

CVE-2025-33013

IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, 3.6.0, and MQ Operator SC2 3.2.0 through 3.2.13 Container could disclose sensitive information to a local user due to improper clearing of heap memory before release.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Data is provided by the National Vulnerability Database (NVD)
IbmMq Operator SwEditionlts Version >= 2.0.0 <= 2.0.29
IbmMq Operator SwEditionsc2 Version >= 3.2.0 <= 3.2.13
IbmMq Operator SwEditioncd Version >= 3.5.1 <= 3.6.0
IbmMq Operator Version3.3.0 SwEditioncd
IbmMq Operator Version3.4.0 SwEditioncd
IbmMq Operator Version3.4.1 SwEditioncd
IbmMq Operator Version3.5.0 SwEditioncd
IbmSupplied Mq Advanced Container Images Version9.3.0.0 Updater1 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.0 Updater2 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.0 Updater3 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.1 Updater1 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.1 Updater2 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.1 Updater3 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.1 Updater4 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.3 Updater1 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.4 Updater1 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.4 Updater2 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.5 Updater1 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.5 Updater2 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.5 Updater3 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.6 Updater1 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.10 Updater1 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.10 Updater2 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.11 Updater1 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.11 Updater2 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.15 Updater1 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.16 Updater1 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.16 Updater2 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.17 Updater1 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.17 Updater2 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.17 Updater3 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.20 Updater1 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.20 Updater2 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.21 Updater1 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.21 Updater2 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.21 Updater3 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.25 Updater1 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.4.0.0 Updater1 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.4.0.0 Updater2 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.4.0.0 Updater3 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.4.0.5 Updater1 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.4.0.5 Updater2 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.4.0.6 Updater1 SwEditionsc2
IbmSupplied Mq Advanced Container Images Version9.4.0.6 Updater2 SwEditionsc2
IbmSupplied Mq Advanced Container Images Version9.4.0.7 Updater1 SwEditionsc2
IbmSupplied Mq Advanced Container Images Version9.4.0.10 Updater1 SwEditionsc2
IbmSupplied Mq Advanced Container Images Version9.4.0.10 Updater2 SwEditionsc2
IbmSupplied Mq Advanced Container Images Version9.4.0.11 Updater1 SwEditionsc2
IbmSupplied Mq Advanced Container Images Version9.4.0.11 Updater2 SwEditionsc2
IbmSupplied Mq Advanced Container Images Version9.4.0.11 Updater3 SwEditionsc2
IbmSupplied Mq Advanced Container Images Version9.4.1.0 Updater1 SwEditioncd
IbmSupplied Mq Advanced Container Images Version9.4.1.0 Updater2 SwEditioncd
IbmSupplied Mq Advanced Container Images Version9.4.1.1 Updater1 SwEditioncd
IbmSupplied Mq Advanced Container Images Version9.4.2.0 Updater1 SwEditioncd
IbmSupplied Mq Advanced Container Images Version9.4.2.0 Updater2 SwEditioncd
IbmSupplied Mq Advanced Container Images Version9.4.2.1 Updater1 SwEditioncd
IbmSupplied Mq Advanced Container Images Version9.4.2.1 Updater2 SwEditioncd
IbmSupplied Mq Advanced Container Images Version9.4.3.0 Updater1 SwEditioncd
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.02% 0.027
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
psirt@us.ibm.com 6.2 2.5 3.6
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-212 Improper Removal of Sensitive Information Before Storage or Transfer

The product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors.

CWE-244 Improper Clearing of Heap Memory Before Release ('Heap Inspection')

Using realloc() to resize buffers that store sensitive information can leave the sensitive information exposed to attack, because it is not removed from memory.