Stack-based buffer overflow in IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - CVE-2025-36097

 

Stack-based buffer overflow in IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - CVE-2025-36097

Published: July 18, 2025


Vulnerability identifier: #VU113074
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-36097
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to a stack-based overflow. A remote unauthenticated attacker can send a specially crafted request that cause the server to consume excessive memory resources.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

IBM WebSphere Application Server
IBM WebSphere Application Server Liberty
IBM Tivoli Network Manager (ITNM)
Enterprise Application Runtimes
Operations Analytics - Log Analysis
PowerVM NovaLink
Cloud Pak for Applications
WebSphere Hybrid Edition
IBM Tivoli Netcool Configuration Manager
Engineering Test Management
Tivoli Composite Application Manager for Application Diagnostics
Control Desk
Business Monitor
Maximo Application Suite - Monitor Component
IBM OpenPages with Watson
Maximo Application Suite - Predict Component
Verify Identity Access Digital Credentials
DevOps Code ClearCase
Business Automation Insights
Application Modernization Accelerator
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
watsonx Assistant Cartridge
Storage Protect Operations Center
Storage Protect for Virtual Environments: Data Protection for Hyper-V
Storage Protect for Space Management
Storage Protect for Virtual Environments: Data Protection for VMware
Storage Protect Client
Voice Gateway
Jazz for Service Management
Log Analysis
Netcool Operations Insight
IBM Cloud Transformation Advisor
IBM Security Guardium Key Lifecycle Manager (GKLM)
IBM Tivoli System Automation Application Manager
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Spectrum Control
IBM Sterling Partner Engagement Manager
IBM Tivoli Netcool Impact
IBM Maximo Asset Management
IBM Cloud Application Performance Management (APM)
IBM TXSeries for Multiplatforms
IBM SPSS Collaboration and Deployment Services
WebSphere Remote Server
IBM Maximo Application Suite - Manage Component
IBM Maximo Application Suite
IBM Rational ClearCase
IBM Rational ClearQuest
InfoSphere Master Data Management
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
IBM Security Verify Access
IBM CICS TX Advanced
IBM CICS TX Standard

How to mitigate CVE-2025-36097

Install updates from vendor's website.

IBM WebSphere Application Server - update to 9.0.5.25
IBM WebSphere Application Server Liberty - update to 25.0.0.8
Voice Gateway - addressed in versions 1.0.8.17, 1.0.8.21
Operations Analytics - Log Analysis - update to 1.3.8.2
Netcool Operations Insight - update to 1.6.15
PowerVM NovaLink - addressed in versions 2.1.1-251007, 2.2.1.1-251007, 2.3.1-251007
IBM Cloud Transformation Advisor - update to 4.4.0
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.2.1
IBM Spectrum Control - update to 5.4.13.2
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.5, 6.2.4.2
IBM Tivoli Netcool Impact - update to 7.1.0.37
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.19
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.29, 8.7.23, 9.0.16, 9.1.2
IBM Maximo Application Suite - addressed in versions 8.10.29, 8.11.26, 9.0.15, 9.1.3
Maximo Application Suite - Monitor Component - addressed in versions 8.10.25, 8.11.23, 9.0.15, 9.1.5
Maximo Application Suite - Predict Component - update to 9.1.1
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
IBM Business Automation Workflow - addressed in versions 24.0.0-IF007, 24.0.1-IF005, 25.0.0-IF002
IBM Cloud Pak for Business Automation - addressed in versions 24.0.1-IF006, 25.0.0-IF003
Application Modernization Accelerator - update to 4.4.0
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.3.0
watsonx Assistant Cartridge - update to 5.3.0
Storage Protect Operations Center - update to 8.1.27.100
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.2.1
Storage Protect for Space Management - update to 8.2.1
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.2.1
Storage Protect Client - update to 8.2.1
IBM CICS TX Advanced - addressed in versions 10.1.0.0 ifix42, 11.1.0.0 ifix34
IBM CICS TX Standard - update to 11.1.0.0 ifix35

External References

Related Security Bulletins