CVE-2025-33013
IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, 3.6.0, and MQ Operator SC2 3.2.0 through 3.2.13 Container could disclose sensitive information to a local user due to improper clearing of heap memory before release.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.2
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS probability
- 0.13%
- CWE
- CWE-244
- Published
- 2025-07-24
- Last modified
- 2026-03-13
Affected products
- IBM MQ Operator
- IBM MQ Operator
- IBM MQ Operator
Weakness type
Related vulnerabilities
- CVE-2026-20349 — Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability
- CVE-2026-48025 — nebula-mesh: Decrypted CA private key persists in heap after signing
- CVE-2026-20039 — Cisco Adaptive Security Appliance and Firepower Threat Defense Software SSL VPN Authentication Denial of Service Vulnerability
- CVE-2025-33101 — Multiple Vulnerabilities in IBM Concert Software.
- CVE-2025-1722 — Multiple Vulnerabilities in IBM Concert Software
- CVE-2025-1719 — Multiple Vulnerabilities in IBM Concert Software
- CVE-2025-1721 — BM Concert Software Improper Clearing of Heap Memory Before Release.
- CVE-2025-36118 — IBM Storage Virtualize Information Disclosure