IBM MQ Password Disclosure Vulnerability in Client Configuration Files

Vulnerability

A password disclosure vulnerability has been identified in IBM MQ versions 9.1.0.0 through 9.1.0.29, 9.2.0.0 through 9.2.0.36, 9.3.0.0 through 9.3.0.30, and 9.4.0.0 through 9.4.0.12, as well as in IBM MQ CD versions 9.3.0.0 through 9.3.5.1 and 9.4.0.0 through 9.4.3.0. When tracing is enabled, the Java and JMS components of IBM MQ store passwords in client configuration files, where they can be accessed by local users.

Impact

Exploitation of this vulnerability allows local users to read stored passwords from client configuration files, potentially leading to unauthorized access or actions within IBM MQ.

Remediation

Users can upgrade to IBM MQ version 9.1.0.31, 9.2.0.37, 9.3.0.31, or 9.4.0.15. For IBM MQ version 9.3 CD and 9.4 CD, upgrade to IBM MQ version 9.4.3.1.

Added: Sep 7, 2025, 1:32 AM
Updated: Sep 7, 2025, 1:32 AM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
2.5
exploitability
3.5
remediation
7.7
relevance
0.5
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.