CVE-2025-36097: IBM WebSphere Application Server denial of service
IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 are vulnerable to a denial of service, caused by a stack-based overflow. An attacker can send a specially crafted request that cause the server to consume excessive memory resources.
Other sources
IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to a denial of service, caused by a stack-based overflow. An attacker can send a specially crafted request that cause the server to consume excessive memory resources.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server Libertyto a version that resolves this vulnerability.Fixed in 25.0.0.8 - Upgrade
Upgrade
IBM WebSphere Application Server 9.0to a version that resolves this vulnerability.Fixed in 9.0.5.25 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch PH67120 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch PH67183
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36097?
CVE-2025-36097 has a high severity rating, as it allows for a denial of service attack through a stack-based overflow.
How do I fix CVE-2025-36097?
To fix CVE-2025-36097, upgrade IBM WebSphere Application Server or WebSphere Application Server Liberty to a version that is not affected by the vulnerability.
What versions are affected by CVE-2025-36097?
CVE-2025-36097 affects IBM WebSphere Application Server version 9.0 and WebSphere Application Server Liberty versions 17.0.0.3 through 25.0.0.7.
What type of attack is associated with CVE-2025-36097?
CVE-2025-36097 is associated with a denial of service attack resulting from an excessive memory consumption due to a stack-based overflow.
Who should be concerned about CVE-2025-36097?
Organizations using IBM WebSphere Application Server or WebSphere Application Server Liberty within the affected versions should be concerned about CVE-2025-36097.