CVE Vulnerabilities

CVE-2023-47745

Cleartext Transmission of Sensitive Information

Published: Mar 03, 2024 | Modified: Dec 23, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM MQ Operator 2.0.0 LTS, 2.0.18 LTS, 3.0.0 CD, 3.0.1 CD, 2.4.0 through 2.4.7, 2.3.0 through 2.3.3, 2.2.0 through 2.2.2, and 2.3.0 through 2.3.3 stores or transmits user credentials in plain clear text which can be read by a local user using a trace command. IBM X-Force ID: 272638.

Weakness

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Affected Software

NameVendorStart VersionEnd Version
Mq_operatorIbm2.2.0 (including)2.2.2 (including)
Mq_operatorIbm2.3.0 (including)2.3.3 (including)
Mq_operatorIbm2.4.0 (including)2.4.7 (including)
Mq_operatorIbm2.0.0 (including)2.0.0 (including)
Mq_operatorIbm2.0.18 (including)2.0.18 (including)
Mq_operatorIbm3.0.0 (including)3.0.0 (including)
Mq_operatorIbm3.0.1 (including)3.0.1 (including)

Potential Mitigations

References