CVE-2025-0985
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Feb 28, 2025
CWE ID 526
Summary
CVE-2025-0985 is a vulnerability affecting IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD. This issue permits local users to access potentially sensitive information stored in environment variables. The vulnerability poses a risk to the confidentiality of data handled by the affected software. IBM has released patches to address this issue, and users are strongly encouraged to apply these updates promptly to mitigate the risk. Failure to do so may lead to unauthorized access to sensitive information.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- IBM MQ
Affected Vendors
- IBM Corporation