CVE-2025-36041

IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1 through 3.5.3, and MQ Operator SC2 3.2.0 through 3.2.12 Native HA CRR could be configured with a private key and chain other than the intended key which could disclose sensitive information or allow the attacker to perform unauthorized actions.
Configurations

No configuration.

History

15 Jun 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-15 13:15

Updated : 2025-06-15 13:15


NVD link : CVE-2025-36041

Mitre link : CVE-2025-36041

CVE.ORG link : CVE-2025-36041


JSON object : View

Products Affected

No product.

CWE
CWE-295

Improper Certificate Validation