Vulnerability Description
IBM MQ LTS 9.1.0.0 through 9.1.0.29, 9.2.0.0 through 9.2.0.36, 9.3.0.0 through 9.3.0.30 and 9.4.0.0 through 9.4.0.12 and IBM MQ CD 9.3.0.0 through 9.3.5.1 and 9.4.0.0 through 9.4.3.0 Java and JMS stores a password in client configuration files when trace is enabled which can be read by a local user.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Mq | >= 9.1.0.0, < 9.1.0.31 |
Related Weaknesses (CWE)
References
- https://www.ibm.com/support/pages/node/7243544PatchVendor Advisory
FAQ
What is CVE-2025-36100?
CVE-2025-36100 is a vulnerability with a CVSS score of 5.1 (MEDIUM). IBM MQ LTS 9.1.0.0 through 9.1.0.29, 9.2.0.0 through 9.2.0.36, 9.3.0.0 through 9.3.0.30 and 9.4.0.0 through 9.4.0.12 and IBM MQ CD 9.3.0.0 through 9.3.5.1 and 9.4.0.0 through 9.4.3.0 Java and JMS sto...
How severe is CVE-2025-36100?
CVE-2025-36100 has been rated MEDIUM with a CVSS base score of 5.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-36100?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Mq.