目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2025-36041 PoC — IBM MQ Operator 信任管理问题漏洞

来源
关联漏洞
标题: IBM MQ Operator 信任管理问题漏洞 (CVE-2025-36041)
Description:IBM MQ Operator是美国国际商业机器(IBM)公司的一种用于管理 IBM MQ 队列管理器生命周期的工具。 IBM MQ Operator存在信任管理问题漏洞,该漏洞源于配置不当可能导致敏感信息泄露或未授权操作。以下版本受到影响:IBM MQ Operator LTS 2.0.0至2.0.29版本,CD 3.0.0版本、3.0.1版本、3.1.0至3.1.3版本、3.3.0版本、3.4.0版本、3.4.1版本、3.5.0版本、3.5.1至3.5.3版本和SC2 3.2.0至3.2.12版本。
Description
Exploit (C) of the CVE-2025-36041 vulnerability in IBM MQ
介绍
# CVE-2025-36041 IBM MQ SSL Bypass Exploit

## Overview

This repository contains a proof-of-concept (PoC) exploit for **CVE-2025-36041**, a vulnerability in IBM MQ (Message Queue) that allows bypassing SSL certificate validation. By injecting a fake SSL certificate and using customized MQCONNX parameters, an unauthorized client connection to an IBM MQ server can be established.

## Features

* **SSL Bypass**: Injects a fake SSL KeyRepository to disable server certificate validation.
* **Automated Exploit**: Opens a specified queue and sends a test message (`"Hello MQ"`) to confirm successful exploitation.
* **Customizable**: Specify the target queue manager, queue name, and path to the fake SSL repository via command-line arguments.

## Prerequisites

* **IBM MQ Client SDK** (headers and libraries)
* **argparse.h** (for command-line parsing)
* **GCC** (or compatible C compiler)

Ensure IBM MQ client libraries are installed and environment variables (`MQ_INCLUDE_PATH`, `MQ_LIB_PATH`) are set accordingly.

## Building

gcc exploit.c argparse.c -o CVE-2025-36041 \
    -I/path/to/mqm/include \
    -L/path/to/mqm/lib -lmqm


## Usage

./CVE-2025-36041 \
    -p /path/to/fake/ssl \
    -n TARGET.QUEUE.NAME \
    -m QM1

**Parameters:**

* `-p, --path`    Path to the fake SSL KeyRepository directory.
* `-n, --name`    Target queue name to open and send message.
* `-m, --qmgr`    Queue Manager name.

## Example


./CVE-2025-36041 -p ./fake_ssl_repo -n MY.QUEUE -m QM1


If successful, you will see:


[+] Starting connection to IBM MQ...
[+] Connected successfully with fake SSL!
[+] Message sent successfully!

## Disclaimer

**For authorized penetration testing and educational purposes only.**
Unauthorized use of this PoC may violate local laws and regulations. The author assumes no liability for misuse.

---

*Author:* Byte Reaper
*CVE:* CVE-2025-36041

文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →