CVE-2014-4822

low
Published 2014-10-19 · Modified 2026-05-06
CVSS v3
CVSS v2
1.9
VIR risk
1.9

Description

IBM WebSphere MQ classes for Java libraries 8.0 before 8.0.0.1 and Websphere MQ Explorer 7.5 before 7.5.0.5 and 8.0 before 8.0.0.2 allow local users to discover preconfigured cleartext passwords via an unspecified trace operation.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg21686339

Application impact

VendorProductVersionsFixed
ibm ibmwebsphere_mq8.0.0.0
ibm ibmwebsphere_mq_explorer7.5.0.0
ibm ibmwebsphere_mq_explorer7.5.0.1
ibm ibmwebsphere_mq_explorer7.5.0.2
ibm ibmwebsphere_mq_explorer7.5.0.3
ibm ibmwebsphere_mq_explorer7.5.0.4
ibm ibmwebsphere_mq_explorer8.0.0.0
ibm ibmwebsphere_mq_explorer8.0.0.1

References

CWEs

CWE-255

Verify integrity in audit chain (admin only). AS-IS.