Privilege Chaining in IBM WebSphere Application Server Liberty - CVE-2025-36124

 

Privilege Chaining in IBM WebSphere Application Server Liberty - CVE-2025-36124

Published: August 13, 2025


Vulnerability identifier: #VU114006
CSH Severity: High
CVSS v4: 8.3 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-36124
CWE-ID: CWE-268
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass security restrictions.

The vulnerability exists due to failure to honor JMS messaging configuration. A remote attacker can trigger the vulnerability to bypass security restrictions


Affected software

IBM WebSphere Application Server Liberty
Enterprise Application Runtimes
Operations Analytics - Log Analysis
PowerVM NovaLink
WebSphere Hybrid Edition
Cloud Pak for Applications
Maximo Application Suite - Monitor Component
IBM OpenPages with Watson
Maximo Application Suite - Predict Component
Verify Identity Access Digital Credentials
Business Automation Insights
Storage Protect Operations Center
Storage Protect Client
Storage Protect for Virtual Environments: Data Protection for VMware
Storage Protect for Space Management
Storage Protect for Virtual Environments: Data Protection for Hyper-V
Voice Gateway
Log Analysis
Netcool Operations Insight
IBM Sterling Partner Engagement Manager
IBM Tivoli Netcool Impact
IBM Cloud Application Performance Management (APM)
IBM TXSeries for Multiplatforms
IBM SPSS Collaboration and Deployment Services
IBM Maximo Application Suite
IBM Business Automation Workflow
IBM Spectrum Symphony
IBM Security Verify Access
IBM CICS TX Advanced
IBM CICS TX Standard

How to mitigate CVE-2025-36124

Install updates from vendor's website.

IBM WebSphere Application Server Liberty - update to 25.0.0.9
Voice Gateway - addressed in versions 1.0.8.17, 1.0.8.21
Log Analysis - update to 1.3.8.2
Operations Analytics - Log Analysis - update to 1.3.8.2
Netcool Operations Insight - update to 1.6.15
PowerVM NovaLink - addressed in versions 2.1.1-251007, 2.2.1.1-251007, 2.3.1-251007
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.5, 6.2.4.2
IBM Tivoli Netcool Impact - update to 7.1.0.37
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.19
IBM TXSeries for Multiplatforms - update to 11.1.0.0 ifix12
IBM Maximo Application Suite - addressed in versions 8.10.31, 8.11.28, 9.0.17, 9.1.6
Maximo Application Suite - Monitor Component - addressed in versions 8.10.23, 8.11.21, 9.0.13, 9.1.3
Maximo Application Suite - Predict Component - update to 9.1.3
IBM Business Automation Workflow - addressed in versions 24.0.0-IF007, 24.0.1-IF005, 25.0.0-IF002
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.6, 25.0.0.0.3
IBM Spectrum Symphony - update to 7.3.2 Fix 602620
Storage Protect Operations Center - update to 8.1.27.100
Storage Protect Client - update to 8.2.1
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.2.1
Storage Protect for Space Management - update to 8.2.1
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.2.1
IBM CICS TX Advanced - addressed in versions 10.1.0.0 ifix43, 11.1.0.0 ifix35
IBM CICS TX Standard - update to 11.1.0.0 ifix36

External References

Related Security Bulletins