
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-36100 is an information disclosure vulnerability in IBM MQ Java and JMS clients classified as "Password in Configuration File" (CWE-260). When trace/debug logging is enabled, IBM MQ stores plaintext passwords in client configuration files that can be read by any local user on the system. Affected versions include IBM MQ LTS 9.1.0.0–9.1.0.29, 9.2.0.0–9.2.0.36, 9.3.0.0–9.3.0.30, and 9.4.0.0–9.4.0.12, as well as IBM MQ CD 9.3.0.0–9.3.5.1 and 9.4.0.0–9.4.3.0. The vulnerability was published on September 7, 2025, with a CVSS v3.1 base score of 5.5 (Medium) (IBM Advisory, Red Hat CVE).
The root cause is CWE-260 (Password in Configuration File): IBM MQ's Java and JMS client libraries write connection passwords in plaintext to client-side configuration or trace files when the trace feature is enabled. This is a local attack vector (AV:L) requiring low privileges (PR:L), meaning any authenticated local user who can read the trace output files can extract stored credentials without any user interaction. No network access or elevated privileges are required beyond basic local system access, making the precondition simply that trace logging has been activated on the affected MQ client (IBM Advisory, Red Hat CVE).
Successful exploitation results in a high confidentiality impact — specifically, the exposure of MQ connection passwords stored in trace files — with no integrity or availability impact. A local attacker who reads these credentials could use them to authenticate to IBM MQ brokers or connected backend systems, potentially enabling unauthorized message queue access, data interception, or lateral movement to other systems that share the same credentials. The scope is limited to the local system where trace files reside, but credential reuse could extend the blast radius beyond the initial host (IBM Advisory).
MQJMS_TRACE_LEVEL, trace configuration files) to verify that Java/JMS trace logging is active.com.ibm.msg.client.commonservices.trace.outputName or similar properties).grep the trace files for password-related strings (e.g., password, passwd, credential fields) to retrieve plaintext MQ connection passwords.*.trc, mqjms*.log, or paths configured in MQ trace settings) by users other than the MQ service account.auditd) showing low-privileged users opening or copying MQ trace output files; file access events on trace directories from unexpected user accounts.grep, cat, strings, find) run by non-MQ users targeting IBM MQ installation or trace output directories.IBM has released patched versions addressing this vulnerability: IBM MQ LTS 9.1.0.31, 9.2.0.37, 9.3.0.31, and 9.4.0.15; IBM MQ CD 9.3.5.2 (or later) and 9.4.3.1 (or later). Organizations should upgrade to these fixed versions as the primary remediation. As interim workarounds: disable trace/debug logging on IBM MQ Java and JMS clients when not actively needed for troubleshooting; restrict file system permissions on trace output directories so only the MQ service account can read them; and rotate any MQ passwords that may have been exposed in existing trace files (IBM Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."