CVE-2025-0985: IBM MQ information disclosure
IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD
stores potentially sensitive information in environment variables that could be obtained by a local user.
Other sources
IBM MQ stores potentially sensitive information in environment variables that could be obtained by a local user.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0985?
CVE-2025-0985 is classified as a medium severity vulnerability due to the risk of sensitive information exposure.
How do I fix CVE-2025-0985?
To fix CVE-2025-0985, review environment variable usage and restrict access to sensitive information.
Who is affected by CVE-2025-0985?
CVE-2025-0985 affects users of IBM MQ versions 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD.
What information can be exposed due to CVE-2025-0985?
CVE-2025-0985 can expose potentially sensitive information stored in environment variables.
Can a remote attacker exploit CVE-2025-0985?
No, CVE-2025-0985 requires local access to exploit the information stored in environment variables.