CVE Vulnerabilities

CVE-2023-47745

Cleartext Transmission of Sensitive Information

Published: Mar 03, 2024 | Modified: Dec 23, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

IBM MQ Operator 2.0.0 LTS, 2.0.18 LTS, 3.0.0 CD, 3.0.1 CD, 2.4.0 through 2.4.7, 2.3.0 through 2.3.3, 2.2.0 through 2.2.2, and 2.3.0 through 2.3.3 stores or transmits user credentials in plain clear text which can be read by a local user using a trace command. IBM X-Force ID: 272638.

Weakness

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Affected Software

Name Vendor Start Version End Version
Mq_operator Ibm 2.2.0 (including) 2.2.2 (including)
Mq_operator Ibm 2.3.0 (including) 2.3.3 (including)
Mq_operator Ibm 2.4.0 (including) 2.4.7 (including)
Mq_operator Ibm 2.0.0 (including) 2.0.0 (including)
Mq_operator Ibm 2.0.18 (including) 2.0.18 (including)
Mq_operator Ibm 3.0.0 (including) 3.0.0 (including)
Mq_operator Ibm 3.0.1 (including) 3.0.1 (including)

Potential Mitigations

References