CVE-2025-1333

MEDIUM

IBM MQ Operator 2.0.0-2.0.29 3.1.0-3.1.3 3.2.0-3.2.10 - Information Disclosure via Cloud Pak for Integration Keycloak

Title source: llm
STIX 2.1

Description

IBM MQ Container when used with the IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, and MQ Operator SC2 3.2.0 through 3.2.10 and configured with Cloud Pak for Integration Keycloak could disclose sensitive information to a privileged user.

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory patch
https://www.ibm.com/support/pages/node/7232272

Scores

CVSS v3 6.0
EPSS 0.0016
EPSS Percentile 35.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-214
Status published
Products (21)
ibm/mq_operator 3.0.0
ibm/mq_operator 3.0.1
ibm/mq_operator 3.3.0
ibm/mq_operator 3.4.0
ibm/mq_operator 3.4.1
ibm/mq_operator 3.5.0
ibm/mq_operator 3.5.1
ibm/mq_operator 2.0.0 - 2.0.29
ibm/mq_operator 2.2.0 - 2.2.2
ibm/mq_operator 3.1.0 - 3.1.3
... and 11 more
Published May 01, 2025
Tracked Since Feb 18, 2026