CVE-2025-36100: IBM MQ information disclosure

Published Sep 7, 2025
·
Updated

IBM MQ Java and JMS stores a password in client configuration files when trace is enabled which can be read by a local user.

Other sources

IBM MQ LTS 9.1.0.0 through 9.1.0.29, 9.2.0.0 through 9.2.0.36, 9.3.0.0 through 9.3.0.30 and 9.4.0.0 through 9.4.0.12 and IBM MQ CD 9.3.0.0 through 9.3.5.1 and 9.4.0.0 through 9.4.3.0  Java and JMS stores a password in client configuration files when trace is enabled which can be read by a local user.

MITRE

Affected Software

13 affected components
IBM MQ>=9.1.0.0<=9.1.0.29, >=9.2.0.0<=9.2.0.36, >=9.3.0.0<=9.3.0.30, >=9.4.0.0<=9.4.0.12, >=9.3.0.0<=9.3.5.1, >=9.4.0.0<=9.4.3.0
IBM MQ<=9.1.0.0 to 9.1.0.29 LTS
IBM MQ<=9.2.0.0 to 9.2.0.36 LTS
IBM MQ<=9.3.0.0 to 9.3.0.30 LTS
IBM MQ<=9.3.0.0 to 9.3.5.1 CD
IBM MQ<=9.4.0.0 to 9.4.0.12 LTS
IBM MQ<=9.4.0.0 to 9.4.3.0 CD
IBM MQ>=9.1.0.0<9.1.0.31
IBM MQ>=9.2.0.0<9.2.0.37
IBM MQ>=9.3.0.0<9.3.0.31
IBM MQ>=9.3.0.0<=9.3.5.1
IBM MQ>=9.4.0.0<9.4.0.15
IBM MQ>=9.4.0.0<9.4.3.1

Remediation

Information

This issue was addressed under known issue DT444585 IBM MQ version 9.1 LTS Apply cumulative security update 9.1.0.31 https://www.ibm.com/support/pages/downloading-ibm-mq-91-lts IBM MQ version 9.2 LTS Apply cumulative security update 9.2.0.37 https://www.ibm.com/support/pages/downloading-ibm-mq-92-lts   IBM MQ version 9.3 LTS Apply cumulative security update 9.3.0.31 https://www.ibm.com/support/pages/downloading-ibm-mq-93-lts IBM MQ version 9.4 LTS Apply fix pack 9.4.0.15 https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts IBM MQ version 9.3 CD and 9.4 CD Upgrade to IBM MQ version 9.4.3.1 https://www.ibm.com/support/pages/downloading-ibm-mq-94-cd

Event History

Sep 7, 2025
CVE Published
via MITRE·12:37 AM
Data Sourced
via MITRE·12:37 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via IBM·12:43 AM
DescriptionAffected Software
Data Sourced
via NVD·01:15 AM
RemedyDescriptionSeverityWeaknessAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

What is the severity of CVE-2025-36100?

CVE-2025-36100 has a medium severity due to the exposure of sensitive information in client configuration files.

2

How do I fix CVE-2025-36100?

To fix CVE-2025-36100, disable tracing in the IBM MQ client configuration to prevent passwords from being stored in the configuration files.

3

Which versions of IBM MQ are affected by CVE-2025-36100?

CVE-2025-36100 affects IBM MQ versions 9.1.0.0 through 9.1.0.29, 9.2.0.0 through 9.2.0.36, 9.3.0.0 through 9.3.0.30, and 9.4.0.0 through 9.4.0.12.

4

What types of users can exploit CVE-2025-36100?

CVE-2025-36100 can be exploited by local users who have access to the client configuration files.

5

Is there a workaround for CVE-2025-36100?

A potential workaround for CVE-2025-36100 is to restrict access to the configuration files to limit exposure of stored passwords.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203