CVE-2025-36047: IBM WebSphere Application Server Liberty denial of service
IBM WebSphere Application Server Liberty 18.0.0.2 through 25.0.0.8 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server Libertyto a version that resolves this vulnerability.Fixed in 25.0.0.9 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch PH66953 - Compensating control
For IBM WebSphere Application Server Liberty 18.0.0.2 through 25.0.0.8 with servlet-3.1, servlet-4.0, servlet-5.0, or servlet-6.0 feature(s) and HTTP/2 protocol enabled, ensure you apply an interim fix or fix pack that contains the fix for APAR PH66953 (DoS via specially-crafted request).
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36047?
The severity of CVE-2025-36047 is categorized as a Denial of Service vulnerability.
How do I fix CVE-2025-36047?
To mitigate CVE-2025-36047, upgrade IBM WebSphere Application Server Liberty to a version later than 25.0.0.8.
What versions of IBM WebSphere Application Server Liberty are affected by CVE-2025-36047?
CVE-2025-36047 affects IBM WebSphere Application Server Liberty versions from 18.0.0.2 to 25.0.0.8.
What can an attacker do with CVE-2025-36047?
An attacker can exploit CVE-2025-36047 to send specially-crafted requests that cause the server to consume excessive memory resources, leading to denial of service.
Is CVE-2025-36047 remotely exploitable?
Yes, CVE-2025-36047 is remotely exploitable, allowing attackers to execute the attack from a remote location.