CVE-2025-36097

7.5

IBM · WebSphere Application Server

IBM WebSphere Application Server contains a stack-based buffer overflow vulnerability that allows an unauthenticated attacker to trigger a denial of service via memory exhaustion.

Executive summary

A stack-based buffer overflow in IBM WebSphere Application Server allows remote, unauthenticated attackers to cause a denial of service by sending specially crafted requests.

Vulnerability

This vulnerability is a stack-based buffer overflow (CWE-121) triggered by sending a specially crafted request to the server. The vulnerability is exploitable by an unauthenticated attacker over the network with no user interaction required.

Business impact

Successful exploitation of this vulnerability results in a denial of service, which can cause significant disruption to business operations and service availability. Given the CVSS score of 7.5, this high-severity flaw poses a direct risk to infrastructure stability, as the ability for an unauthenticated remote attacker to crash critical application servers can lead to prolonged downtime and loss of productivity.

Remediation

Immediate Action: Upgrade to the required minimal fix pack levels and apply the specified Interim Fix for PH67183, or update to Fix Pack 25.0.0.8 or later for Liberty environments.

Proactive Monitoring: Monitor server logs for repeated connection failures or memory usage spikes that may indicate attempts to trigger the overflow condition.

Compensating Controls: Deploy a Web Application Firewall (WAF) configured to inspect and block malformed JSON payloads or requests that exhibit irregular memory consumption patterns.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability represents a significant risk to the availability of IBM WebSphere environments. Organizations must prioritize the application of the vendor-supplied patches as soon as they are available to prevent potential service degradation. Given the ease of exploitation, administrators should treat this update with high urgency and verify that all affected nodes in their cluster are updated to the recommended fix pack levels.

More IBM CVEs

Sources