IBM MQ
cpe:2.3:a:ibm:mq:*:*:*:*:*:*:*
- >= 9.1.0.0, <= 9.1.0.29
- >= 9.2.0.0, <= 9.2.0.36
- >= 9.3.0.0, <= 9.3.0.30
- >= 9.3.0.0, <= 9.3.5.1
- >= 9.4.0.0, <= 9.4.0.12
- >= 9.4.0.0, <= 9.4.3.0
A password disclosure vulnerability has been identified in IBM MQ versions 9.1.0.0 through 9.1.0.29, 9.2.0.0 through 9.2.0.36, 9.3.0.0 through 9.3.0.30, and 9.4.0.0 through 9.4.0.12, as well as in IBM MQ CD versions 9.3.0.0 through 9.3.5.1 and 9.4.0.0 through 9.4.3.0. When tracing is enabled, the Java and JMS components of IBM MQ store passwords in client configuration files, where they can be accessed by local users.
Exploitation of this vulnerability allows local users to read stored passwords from client configuration files, potentially leading to unauthorized access or actions within IBM MQ.
Users can upgrade to IBM MQ version 9.1.0.31, 9.2.0.37, 9.3.0.31, or 9.4.0.15. For IBM MQ version 9.3 CD and 9.4 CD, upgrade to IBM MQ version 9.4.3.1.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.