IBM MQ Container when used with the IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, and MQ Operator SC2 3.2.0 through 3.2.10 and configured with Cloud Pak for Integration Keycloak could disclose sensitive information to a privileged user.
CVE ID: CVE-2025-1333
CVSS Base Severity: MEDIUM
CVSS Base Score: 6.0
CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Vendor: IBM
Product: MQ Operator
EPSS Score: 0.01% (probability of being exploited)
EPSS Percentile: 1.5% (scored less or equal to compared to others)
EPSS Date: 2025-05-30 (when was this score calculated)