IBM MQ Password Disclosure Vulnerability in Web Console

Vulnerability

A vulnerability in the IBM MQ web console in versions 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow a local user to access sensitive information. This occurs when a detailed technical error message is generated, potentially disclosing passwords or other confidential data.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive information, including passwords, through the generation of detailed error messages that reveal such data.

Remediation

Users can upgrade to IBM MQ version 9.4.1.1. For IBM MQ version 9.3 LTS, cumulative security update 9.3.0.26 is available. Users on IBM MQ version 9.4 LTS should apply cumulative security update 9.4.0.7.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
2.5
exploitability
3.5
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.