PT-2025-18719 · Ibm · Cloud Pak For Integration Keycloak+4
Published
2025-05-01
·
Updated
2025-05-02
·
CVE-2025-1333
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM MQ Container versions 2.0.0 through 2.0.29
IBM MQ Operator LTS versions 2.0.0 through 2.0.29
IBM MQ Operator CD versions 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1
IBM MQ Operator SC2 versions 3.2.0 through 3.2.10
Description
The issue concerns the disclosure of sensitive information to a privileged user when the IBM MQ Container is used with the IBM MQ Operator and configured with Cloud Pak for Integration Keycloak.
Recommendations
For IBM MQ Container versions 2.0.0 through 2.0.29, update to a version that is not affected by this issue.
For IBM MQ Operator LTS versions 2.0.0 through 2.0.29, update to a version that is not affected by this issue.
For IBM MQ Operator CD versions 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, update to a version that is not affected by this issue.
For IBM MQ Operator SC2 versions 3.2.0 through 3.2.10, update to a version that is not affected by this issue.
As a temporary workaround, consider restricting access to the Keycloak authentication module until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cloud Pak For Integration Keycloak
Ibm Mq Container
Ibm Mq Operator
Ibm Mq Operator Lts
Ibm Mq Operator Sc2