Improper Output Neutralization for Logs in IBM MQ Operator and IBM supplied MQ Advanced container images - CVE-2025-12755
Published: February 10, 2026
Vulnerability identifier: #VU122514
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-12755
CWE-ID: CWE-117
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to improper neutralization of special elements when written to log files. A remote attacker can inject data into log messages on the system.
Affected software
IBM MQ Operator
IBM supplied MQ Advanced container images
IBM supplied MQ Advanced container images
How to mitigate CVE-2025-12755
Install updates from vendor's website.
IBM MQ Operator - update to 3.9.0
IBM supplied MQ Advanced container images - addressed in versions 9.4.0.17-r2, 9.4.5.0-r1
IBM supplied MQ Advanced container images - addressed in versions 9.4.0.17-r2, 9.4.5.0-r1