cbcvebase.
CVE-2025-36041
published 2025-06-15

CVE-2025-36041: IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1 through 3.5.3, and MQ Operator…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1 through 3.5.3, and MQ Operator SC2 3.2.0 through 3.2.12 Native HA CRR could be configured with a private key and chain other than the intended key which could disclose sensitive information or allow the attacker to perform unauthorized actions.

Affected

60 ranges· showing 25
VendorProductVersion rangeFixed in
ibmmq_operator
ibmmq_operator
ibmmq_operator
ibmmq_operator
ibmmq_operator
ibmmq_operator
ibmmq_operator
ibmmq_operator2.0.0 – 2.0.29
ibmmq_operator2.0.0 LTS – 2.0.29 LTS
ibmmq_operator2.2.0 – 2.2.2
ibmmq_operator2.3.0 – 2.3.3
ibmmq_operator2.4.0 – 2.4.8
ibmmq_operator3.1.0 – 3.1.3
ibmmq_operator3.2.0 – 3.2.12
ibmmq_operator3.2.0 SC2 – 3.2.10 SC2
ibmmq_operator3.5.1 – 3.5.3
ibmsupplied_mq_advanced_container_images
ibmsupplied_mq_advanced_container_images
ibmsupplied_mq_advanced_container_images
ibmsupplied_mq_advanced_container_images
ibmsupplied_mq_advanced_container_images
ibmsupplied_mq_advanced_container_images
ibmsupplied_mq_advanced_container_images
ibmsupplied_mq_advanced_container_images
ibmsupplied_mq_advanced_container_images