Metrics
Affected Vendors & Products
Solution
IBM strongly recommends addressing the vulnerability now by applying a currently available interim fix or fix pack that contains the fix for APAR PH66953. To determine if a feature is enabled for IBM WebSphere Application Server Liberty, refer to How to determine if Liberty is using a specific feature. To determine if the HTTP/2 protocol is enabled with Liberty Servlet features see HTTP/2 Support for Liberty. For IBM WebSphere Application Server Liberty 18.0.0.2 - 25.0.0.8 using the servlet-3.1, servlet-4.0, servlet-5.0, or servlet-6.0 feature(s) with the HTTP/2 protocol enabled: · Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves PH66953 --OR-- · Apply Liberty Fix Pack 25.0.0.9 or later (targeted availability 3Q2025). Additional interim fixes may be available and linked off the interim fix download page.
Workaround
No workaround given by the vendor.
Link | Providers |
---|---|
https://www.ibm.com/support/pages/node/7242086 |
![]() ![]() |
Mon, 18 Aug 2025 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Apple
Apple macos Ibm aix Ibm i Ibm z\/os Linux Linux linux Kernel Microsoft Microsoft windows |
|
CPEs | cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:liberty:*:*:* cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:* cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:* cpe:2.3:o:ibm:i:-:*:*:*:*:*:*:* cpe:2.3:o:ibm:z\/os:-:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
Vendors & Products |
Apple
Apple macos Ibm aix Ibm i Ibm z\/os Linux Linux linux Kernel Microsoft Microsoft windows |
Thu, 14 Aug 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 14 Aug 2025 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | IBM WebSphere Application Server Liberty 18.0.0.2 through 25.0.0.8 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. | |
Title | IBM WebSphere Application Server Liberty denial of service | |
First Time appeared |
Ibm
Ibm websphere Application Server |
|
Weaknesses | CWE-770 | |
CPEs | cpe:2.3:a:ibm:websphere_application_server:18.0.0.2:*:*:*:liberty:*:*:* cpe:2.3:a:ibm:websphere_application_server:25.0.0.8:*:*:*:liberty:*:*:* |
|
Vendors & Products |
Ibm
Ibm websphere Application Server |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-08-14T19:56:04.637Z
Reserved: 2025-04-15T21:16:10.569Z
Link: CVE-2025-36047

Updated: 2025-08-14T18:44:05.624Z

Status : Analyzed
Published: 2025-08-14T16:15:32.787
Modified: 2025-08-18T17:25:11.113
Link: CVE-2025-36047

No data.

No data.