IBM MQ等都是美国国际商业机器(IBM)公司的产品。IBM MQ是一款消息传递中间件产品。IBM MQ Operator是一种用于管理 IBM MQ 队列管理器生命周期的工具。IBM MQ Container CD是一个IBM MQ的容器化部署方案。 IBM多款产品存在信任管理问题漏洞,该漏洞源于证书验证不当,可能导致敏感信息泄露。以下产品及版本受到影响:IBM MQ Operator LTS 2.0.0至2.0.29版本、MQ Operator CD 3.0.0、3.0.1、3.1.0至3.1.3、
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| IBM | MQ Operator | 2.0.0 LTS ~ 2.0.29 LTS |
cpe:2.3:a:ibm:mq_operator:2.0.0:*:*:*:lts:*:*:*
|
|
| IBM | MQ Operator | 3.0.0, 3.0.1, 3.1.0, 3.1.3, 3.4.0, 3.5.0, 3.5.1, 3.6.0 CD |
cpe:2.3:a:ibm:mq_operator:3.0.0:*:*:*:continuous_delivery:*:*:*
|
|
| IBM | MQ Operator | 3.2.0 SC2 ~ 3.2.13 SC2 |
cpe:2.3:a:ibm:mq_operator:3.2.0:*:*:*:support_cycle_2:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-33109 | 7.5 HIGH | IBM i privilege escalation |
| CVE-2025-33013 | 6.2 MEDIUM | IBM MQ Operator information disclosure |
No comments yet