[CIVN-2025-0150] Denial of Service vulnerability in IBM WebSphere
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Denial of Service vulnerability in IBM WebSphere
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
IBM WebSphere Application Server Liberty versions 17.0.0.3 – 25.0.0.7
IBM WebSphere Application Server version 9.0
Overview
A vulnerability has been reported in IBM WebSphere Application Server Liberty and IBM WebSphere Application Server, which could be exploited by a remote attacker to cause a Denial of Service (DoS) condition on the targeted system.
Target Audience:
All end-users and organisations using IBM WebSphere Application Server Liberty and WebSphere Application Server.
Risk Assessment:
Successful exploitation of this vulnerability could lead to high risks to the confidentiality, integrity, and availability of the affected systems.
Impact Assessment:
Potential for denial-of-service conditions, resource exhaustion, and disruption of application availability.
Description
This vulnerability exists in IBM WebSphere Application Server and Liberty due to a stack-based buffer overflow issue. A remote attacker could exploit this vulnerability by sending malicious input that causes the server to consume excessive memory resources, leading to system instability.
Successful exploitation of this vulnerability could allow the attacker to cause a denial-of-service condition on the targeted system.
Solution
Apply appropriate updates as mentioned in the IBMs portal:
https://www.ibm.com/support/pages/node/7239856
Vendor Information
IBM
https://www.ibm.com/support/pages/node/7239856
References
IBM
https://www.ibm.com/support/pages/node/7239856
CVE Name
CVE-2025-36097
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmh/P7IACgkQ3jCgcSdc
ys8FHBAAkO3IlDr228YBzEZ0+GHKVHPGGfynzkFmPmCgupMkGpMi8KpO5VRi9HL/
cxY5JkoppYgsN+dtz1SVn/m2mriymLLkwiF0NKzkxBGEsQXdorhwVSsZfHp5cTjp
apHU0ghI2slv9y0oDMQMPW1BJBlCZbhWf+vMs49W0Lr28qBlhpFffNPmn6pUw50g
KoPF4pcUc0tqiZfkr24uRO+GOTlX/nUt96scWTNFFOkqmVqOjGv0ZxV2ExKNq4Rd
yb+kejPejv1z2djms1NRntA20YHxJSa5/YDvLRChW2mz3cTTt5DkCYmiKUpzJtig
l/QvfEt3L74sFYFD9pGZ+mofqpk10F0uEEbIzu10F2B9Gw3A7qCMhdWzfgLRmQWl
K6iaMKKqetJvGBBba5NzOkEIRJhCciAtjOwz4q3hTukbIBy8yxgdQS+G61nPDQRH
XzL3tYjV7ChRpXR67qYoY1fqcHc/W65aUwS8ec5Mw47jYfNXGnRWmamAlSfgD6Zp
bcumG3drYjqgRHXJCC7SapasziZq8hclQPmdvl+Ljlt9g31Mwg6eqLEnyZkcvp7p
1ms4mc0NYQCzREpLTTUwyduAR1s0rvRZxzuW7OAJRaa0WViXKvhPPMEBZdKe1d9t
IX5TP11Jd8Bwrkuuqu4tupkWYWKO6KXwcns9aji+UCGbY6CPh0M=
=MThX
—–END PGP SIGNATURE—–