CVE-2022-22325Sensitive Information Exposure in IBM MQ FOR HPE Nonstop

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 88.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 13
Latest updateMay 14

Description

IBM MQ (IBM MQ for HPE NonStop 8.1.0) can inadvertently disclose sensitive information under certain circumstances to a local user from a stack trace. IBM X-Force ID: 218853.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5ibm/mq_for_hpe_nonstop8.1.0
NVDibm/mq8.1.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-g76r-h6q3-xg7q: IBM MQ (IBM MQ for HPE NonStop 82022-05-14
CVEList
CVE-2022-22325: IBM MQ (IBM MQ for HPE NonStop 82022-05-13
CVE-2022-22325 — Sensitive Information Exposure in IBM | cvebase