CVE-2025-36100
IBM WebSphere MQ vulnerability analysis and mitigation

Overview

CVE-2025-36100 is an information disclosure vulnerability in IBM MQ Java and JMS clients classified as "Password in Configuration File" (CWE-260). When trace/debug logging is enabled, IBM MQ stores plaintext passwords in client configuration files that can be read by any local user on the system. Affected versions include IBM MQ LTS 9.1.0.0–9.1.0.29, 9.2.0.0–9.2.0.36, 9.3.0.0–9.3.0.30, and 9.4.0.0–9.4.0.12, as well as IBM MQ CD 9.3.0.0–9.3.5.1 and 9.4.0.0–9.4.3.0. The vulnerability was published on September 7, 2025, with a CVSS v3.1 base score of 5.5 (Medium) (IBM Advisory, Red Hat CVE).

Technical details

The root cause is CWE-260 (Password in Configuration File): IBM MQ's Java and JMS client libraries write connection passwords in plaintext to client-side configuration or trace files when the trace feature is enabled. This is a local attack vector (AV:L) requiring low privileges (PR:L), meaning any authenticated local user who can read the trace output files can extract stored credentials without any user interaction. No network access or elevated privileges are required beyond basic local system access, making the precondition simply that trace logging has been activated on the affected MQ client (IBM Advisory, Red Hat CVE).

Impact

Successful exploitation results in a high confidentiality impact — specifically, the exposure of MQ connection passwords stored in trace files — with no integrity or availability impact. A local attacker who reads these credentials could use them to authenticate to IBM MQ brokers or connected backend systems, potentially enabling unauthorized message queue access, data interception, or lateral movement to other systems that share the same credentials. The scope is limited to the local system where trace files reside, but credential reuse could extend the blast radius beyond the initial host (IBM Advisory).

Exploitation steps

  1. Gain local access: Obtain a low-privileged local user account on a system running an affected IBM MQ Java or JMS client (versions 9.1.0.0–9.1.0.29 LTS, 9.2.0.0–9.2.0.36 LTS, 9.3.0.0–9.3.0.30 LTS, 9.4.0.0–9.4.0.12 LTS, or CD 9.3.0.0–9.3.5.1 / 9.4.0.0–9.4.3.0).
  2. Confirm trace is enabled: Check IBM MQ client configuration or environment variables (e.g., MQJMS_TRACE_LEVEL, trace configuration files) to verify that Java/JMS trace logging is active.
  3. Locate trace output files: Identify the directory where IBM MQ Java/JMS trace files are written (commonly configured via com.ibm.msg.client.commonservices.trace.outputName or similar properties).
  4. Extract credentials: Open or grep the trace files for password-related strings (e.g., password, passwd, credential fields) to retrieve plaintext MQ connection passwords.
  5. Leverage credentials: Use the extracted passwords to authenticate to IBM MQ queue managers or connected systems, potentially enabling unauthorized message access or lateral movement (IBM Advisory).

Indicators of compromise

  • File System: Unexpected access or reads of IBM MQ Java/JMS trace files (e.g., files matching *.trc, mqjms*.log, or paths configured in MQ trace settings) by users other than the MQ service account.
  • Logs: OS audit logs (e.g., Linux auditd) showing low-privileged users opening or copying MQ trace output files; file access events on trace directories from unexpected user accounts.
  • Process: Unusual processes (e.g., grep, cat, strings, find) run by non-MQ users targeting IBM MQ installation or trace output directories.

Mitigation and workarounds

IBM has released patched versions addressing this vulnerability: IBM MQ LTS 9.1.0.31, 9.2.0.37, 9.3.0.31, and 9.4.0.15; IBM MQ CD 9.3.5.2 (or later) and 9.4.3.1 (or later). Organizations should upgrade to these fixed versions as the primary remediation. As interim workarounds: disable trace/debug logging on IBM MQ Java and JMS clients when not actively needed for troubleshooting; restrict file system permissions on trace output directories so only the MQ service account can read them; and rotate any MQ passwords that may have been exposed in existing trace files (IBM Advisory).

Additional resources


SourceThis report was generated using AI

Related IBM WebSphere MQ vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-36128HIGH7.5
  • IBM WebSphere MQ logoIBM WebSphere MQ
  • cpe:2.3:a:ibm:mq
NoYesOct 16, 2025
CVE-2025-36100MEDIUM5.5
  • IBM WebSphere MQ logoIBM WebSphere MQ
  • cpe:2.3:a:ibm:mq
NoYesSep 07, 2025
CVE-2025-0985MEDIUM5.5
  • IBM WebSphere MQ logoIBM WebSphere MQ
  • mq
NoYesFeb 28, 2025
CVE-2024-54175MEDIUM5.5
  • IBM WebSphere MQ logoIBM WebSphere MQ
  • cpe:2.3:a:ibm:mq
NoYesFeb 28, 2025
CVE-2026-1713MEDIUM5
  • IBM WebSphere MQ logoIBM WebSphere MQ
  • cpe:2.3:a:ibm:mq
NoYesMar 03, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management