6.5

CVE-2025-36005

IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, 3.6.0, and MQ Operator SC2 3.2.0 through 3.2.13 Internet Pass-Thru could allow a malicious user to obtain sensitive information from another TLS session connection by the proxy to the same hostname and port due to improper certificate validation.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IbmMq Operator SwEditionlts Version >= 2.0.0 <= 2.0.29
IbmMq Operator SwEditionsc2 Version >= 3.2.0 <= 3.2.13
IbmMq Operator SwEditioncd Version >= 3.5.1 <= 3.6.0
IbmMq Operator Version3.3.0 SwEditioncd
IbmMq Operator Version3.4.0 SwEditioncd
IbmMq Operator Version3.4.1 SwEditioncd
IbmMq Operator Version3.5.0 SwEditioncd
IbmSupplied Mq Advanced Container Images Version9.3.0.0 Updater1 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.0 Updater2 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.0 Updater3 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.1 Updater1 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.1 Updater2 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.1 Updater3 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.1 Updater4 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.3 Updater1 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.4 Updater1 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.4 Updater2 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.5 Updater1 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.5 Updater2 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.5 Updater3 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.6 Updater1 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.10 Updater1 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.10 Updater2 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.11 Updater1 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.11 Updater2 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.15 Updater1 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.16 Updater1 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.16 Updater2 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.17 Updater1 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.17 Updater2 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.17 Updater3 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.20 Updater1 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.20 Updater2 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.21 Updater1 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.21 Updater2 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.21 Updater3 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.3.0.25 Updater1 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.4.0.0 Updater1 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.4.0.0 Updater2 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.4.0.0 Updater3 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.4.0.5 Updater1 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.4.0.5 Updater2 SwEditionlts
IbmSupplied Mq Advanced Container Images Version9.4.0.6 Updater1 SwEditionsc2
IbmSupplied Mq Advanced Container Images Version9.4.0.6 Updater2 SwEditionsc2
IbmSupplied Mq Advanced Container Images Version9.4.0.7 Updater1 SwEditionsc2
IbmSupplied Mq Advanced Container Images Version9.4.0.10 Updater1 SwEditionsc2
IbmSupplied Mq Advanced Container Images Version9.4.0.10 Updater2 SwEditionsc2
IbmSupplied Mq Advanced Container Images Version9.4.0.11 Updater1 SwEditionsc2
IbmSupplied Mq Advanced Container Images Version9.4.0.11 Updater2 SwEditionsc2
IbmSupplied Mq Advanced Container Images Version9.4.0.11 Updater3 SwEditionsc2
IbmSupplied Mq Advanced Container Images Version9.4.1.0 Updater1 SwEditioncd
IbmSupplied Mq Advanced Container Images Version9.4.1.0 Updater2 SwEditioncd
IbmSupplied Mq Advanced Container Images Version9.4.1.1 Updater1 SwEditioncd
IbmSupplied Mq Advanced Container Images Version9.4.2.0 Updater1 SwEditioncd
IbmSupplied Mq Advanced Container Images Version9.4.2.0 Updater2 SwEditioncd
IbmSupplied Mq Advanced Container Images Version9.4.2.1 Updater1 SwEditioncd
IbmSupplied Mq Advanced Container Images Version9.4.2.1 Updater2 SwEditioncd
IbmSupplied Mq Advanced Container Images Version9.4.3.0 Updater1 SwEditioncd
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.03% 0.057
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
psirt@us.ibm.com 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-295 Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.