CVE-2025-36100: IBM MQ information disclosure
IBM MQ Java and JMS stores a password in client configuration files when trace is enabled which can be read by a local user.
Other sources
IBM MQ LTS 9.1.0.0 through 9.1.0.29, 9.2.0.0 through 9.2.0.36, 9.3.0.0 through 9.3.0.30 and 9.4.0.0 through 9.4.0.12 and IBM MQ CD 9.3.0.0 through 9.3.5.1 and 9.4.0.0 through 9.4.3.0 Java and JMS stores a password in client configuration files when trace is enabled which can be read by a local user.
— MITRE
Affected Software
Remediation
Information
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36100?
CVE-2025-36100 has a medium severity due to the exposure of sensitive information in client configuration files.
How do I fix CVE-2025-36100?
To fix CVE-2025-36100, disable tracing in the IBM MQ client configuration to prevent passwords from being stored in the configuration files.
Which versions of IBM MQ are affected by CVE-2025-36100?
CVE-2025-36100 affects IBM MQ versions 9.1.0.0 through 9.1.0.29, 9.2.0.0 through 9.2.0.36, 9.3.0.0 through 9.3.0.30, and 9.4.0.0 through 9.4.0.12.
What types of users can exploit CVE-2025-36100?
CVE-2025-36100 can be exploited by local users who have access to the client configuration files.
Is there a workaround for CVE-2025-36100?
A potential workaround for CVE-2025-36100 is to restrict access to the configuration files to limit exposure of stored passwords.