IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 are vulnerable to a denial of service, caused by a stack-based overflow. An attacker can send a specially crafted request that cause the server to consume excessive memory resources.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-21735 IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 are vulnerable to a denial of service, caused by a stack-based overflow. An attacker can send a specially crafted request that cause the server to consume excessive memory resources.
Fixes

Solution

For IBM WebSphere Application Server Liberty 17.0.0.3 - 25.0.0.7 using the jsonp-1.0, jsonp-1.1, or jsonp-2.0 feature: · Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves PH67183 --OR-- · Apply Fix Pack 25.0.0.8 or later (targeted availability 3Q2025). For IBM WebSphere Application Server traditional: For V9.0.0.0 through 9.0.5.24: · Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves PH67120 --OR-- · Apply Fix Pack 9.0.5.25 or later (targeted availability 3Q2025). Additional interim fixes may be available and linked off the interim fix download page.


Workaround

No workaround given by the vendor.

History

Mon, 11 Aug 2025 19:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:-:*:*:*
cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:liberty:*:*:*

Fri, 18 Jul 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Jul 2025 01:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:websphere_application_server:8.5:*:*:*:*:*:*:*

Wed, 16 Jul 2025 18:00:00 +0000

Type Values Removed Values Added
Description IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 are vulnerable to a denial of service, caused by a stack-based overflow. An attacker can send a specially crafted request that cause the server to consume excessive memory resources.
Title IBM WebSphere Application Server denial of service
First Time appeared Ibm
Ibm websphere Application Server
Weaknesses CWE-121
CPEs cpe:2.3:a:ibm:websphere_application_server:17.0.0.3:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:websphere_application_server:25.0.0.7:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:websphere_application_server:8.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm websphere Application Server
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2025-08-18T01:34:17.799Z

Reserved: 2025-04-15T21:16:14.712Z

Link: CVE-2025-36097

cve-icon Vulnrichment

Updated: 2025-07-18T14:25:05.172Z

cve-icon NVD

Status : Analyzed

Published: 2025-07-16T18:15:24.243

Modified: 2025-08-11T19:17:55.357

Link: CVE-2025-36097

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.