Allocation of Resources Without Limits or Throttling in IBM WebSphere Application Server Liberty - CVE-2025-36047
Published: September 16, 2025
Vulnerability identifier: #VU115568
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-36047
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
IBM WebSphere Application Server Liberty
Voice Gateway
Log Analysis
IBM Cloud Transformation Advisor
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Sterling Partner Engagement Manager
IBM Tivoli Netcool Impact
IBM Cloud Application Performance Management (APM)
IBM TXSeries for Multiplatforms
IBM SPSS Collaboration and Deployment Services
IBM Maximo Application Suite - Manage Component
IBM Maximo Application Suite
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
IBM MQ Operator
IBM Spectrum Symphony
Operations Analytics - Log Analysis
IBM Security Directory Suite
Maximo Application Suite - Monitor Component
IBM OpenPages with Watson
Maximo Application Suite - Predict Component
IBM Security Verify Directory
Verify Identity Access Digital Credentials
Business Automation Insights
Application Modernization Accelerator
Storage Protect Operations Center
Storage Protect Client
Storage Protect for Virtual Environments: Data Protection for VMware
Storage Protect for Space Management
Storage Protect for Virtual Environments: Data Protection for Hyper-V
CICS Transaction Gateway for Multiplatforms
CICS Transaction Gateway Desktop Edition
IBM supplied MQ Advanced container images
IBM Tivoli Application Dependency Discovery Manager
IBM Security Verify Access
IBM InfoSphere Information Server
IBM CICS TX Advanced
IBM CICS TX Standard
Voice Gateway
Log Analysis
IBM Cloud Transformation Advisor
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Sterling Partner Engagement Manager
IBM Tivoli Netcool Impact
IBM Cloud Application Performance Management (APM)
IBM TXSeries for Multiplatforms
IBM SPSS Collaboration and Deployment Services
IBM Maximo Application Suite - Manage Component
IBM Maximo Application Suite
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
IBM MQ Operator
IBM Spectrum Symphony
Operations Analytics - Log Analysis
IBM Security Directory Suite
Maximo Application Suite - Monitor Component
IBM OpenPages with Watson
Maximo Application Suite - Predict Component
IBM Security Verify Directory
Verify Identity Access Digital Credentials
Business Automation Insights
Application Modernization Accelerator
Storage Protect Operations Center
Storage Protect Client
Storage Protect for Virtual Environments: Data Protection for VMware
Storage Protect for Space Management
Storage Protect for Virtual Environments: Data Protection for Hyper-V
CICS Transaction Gateway for Multiplatforms
CICS Transaction Gateway Desktop Edition
IBM supplied MQ Advanced container images
IBM Tivoli Application Dependency Discovery Manager
IBM Security Verify Access
IBM InfoSphere Information Server
IBM CICS TX Advanced
IBM CICS TX Standard
How to mitigate CVE-2025-36047
Install updates from vendor's website.
Voice Gateway - addressed in versions 1.0.8.17, 1.0.8.21
Log Analysis - update to 1.3.8.2
Operations Analytics - Log Analysis - update to 1.3.8.2
IBM Cloud Transformation Advisor - update to 4.4.0
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.0
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.5, 6.2.4.2
IBM Security Directory Suite - update to 8.0.1.24
IBM Tivoli Netcool Impact - update to 7.1.0.37
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.19
IBM TXSeries for Multiplatforms - update to 11.1.0.0 ifix12
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.31, 8.7.25, 9.0.18, 9.1.5
IBM Maximo Application Suite - addressed in versions 8.10.30, 8.11.27, 9.0.16, 9.1.5
Maximo Application Suite - Monitor Component - addressed in versions 8.10.23, 8.11.21, 9.0.13, 9.1.3
Maximo Application Suite - Predict Component - update to 9.1.2
IBM Security Verify Directory - update to 10.0.4.3 IF1
IBM InfoSphere Information Server - update to 11.7.1.6 Service pack 1
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
IBM Business Automation Workflow - addressed in versions 24.0.0-IF007, 24.0.1-IF005, 25.0.0-IF002
IBM Cloud Pak for Business Automation - addressed in versions 24.0.1-IF006, 25.0.0-IF003
IBM MQ Operator - addressed in versions 3.2.19, 3.7.2, 9.4.4.0-r3
Application Modernization Accelerator - update to 4.4.0
IBM Spectrum Symphony - update to 7.3.2 Fix 602620
Storage Protect Operations Center - update to 8.1.27.100
Storage Protect Client - update to 8.2.1
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.2.1
Storage Protect for Space Management - update to 8.2.1
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.2.1
CICS Transaction Gateway for Multiplatforms - addressed in versions 9.2.0.2, 9.3.0.0, 10.1.0.0
CICS Transaction Gateway Desktop Edition - addressed in versions 9.2.0.2, 9.3.0.0, 10.1.0.0
IBM supplied MQ Advanced container images - update to 9.4.4.0-r3
IBM CICS TX Advanced - addressed in versions 10.1.0.0 ifix43, 11.1.0.0 ifix35
IBM CICS TX Standard - update to 11.1.0.0 ifix36
Log Analysis - update to 1.3.8.2
Operations Analytics - Log Analysis - update to 1.3.8.2
IBM Cloud Transformation Advisor - update to 4.4.0
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.0
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.5, 6.2.4.2
IBM Security Directory Suite - update to 8.0.1.24
IBM Tivoli Netcool Impact - update to 7.1.0.37
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.19
IBM TXSeries for Multiplatforms - update to 11.1.0.0 ifix12
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.31, 8.7.25, 9.0.18, 9.1.5
IBM Maximo Application Suite - addressed in versions 8.10.30, 8.11.27, 9.0.16, 9.1.5
Maximo Application Suite - Monitor Component - addressed in versions 8.10.23, 8.11.21, 9.0.13, 9.1.3
Maximo Application Suite - Predict Component - update to 9.1.2
IBM Security Verify Directory - update to 10.0.4.3 IF1
IBM InfoSphere Information Server - update to 11.7.1.6 Service pack 1
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
IBM Business Automation Workflow - addressed in versions 24.0.0-IF007, 24.0.1-IF005, 25.0.0-IF002
IBM Cloud Pak for Business Automation - addressed in versions 24.0.1-IF006, 25.0.0-IF003
IBM MQ Operator - addressed in versions 3.2.19, 3.7.2, 9.4.4.0-r3
Application Modernization Accelerator - update to 4.4.0
IBM Spectrum Symphony - update to 7.3.2 Fix 602620
Storage Protect Operations Center - update to 8.1.27.100
Storage Protect Client - update to 8.2.1
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.2.1
Storage Protect for Space Management - update to 8.2.1
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.2.1
CICS Transaction Gateway for Multiplatforms - addressed in versions 9.2.0.2, 9.3.0.0, 10.1.0.0
CICS Transaction Gateway Desktop Edition - addressed in versions 9.2.0.2, 9.3.0.0, 10.1.0.0
IBM supplied MQ Advanced container images - update to 9.4.4.0-r3
IBM CICS TX Advanced - addressed in versions 10.1.0.0 ifix43, 11.1.0.0 ifix35
IBM CICS TX Standard - update to 11.1.0.0 ifix36
External References
Related Security Bulletins
- Allocation of resources without limits or throttling in IBM WebSphere Application Server Liberty
- Multiple vulnerabilities in IBM SPSS Collaboration and Deployment Services
- Multiple vulnerabilities in IBM Voice Gateway
- Multiple vulnerabilities in IBM Application Modernization Accelerator
- Multiple vulnerabilities in IBM Transformation Advisor
- Multiple vulnerabilities in IBM OpenPages
- Multiple vulnerabilities in IBM CICS TX Advanced
- Multiple vulnerabilities in IBM CICS TX Standard
- Multiple vulnerabilities in IBM TXSeries for Multiplatforms
- Multiple vulnerabilities in IBM Log Analysis
- Multiple vulnerabilities in IBM Tivoli Netcool Impact
- Allocation of resources without limits or throttling in IBM Maximo Application Suite - Predict Component
- Multiple vulnerabilities in IBM Maximo Application Suite
- Multiple vulnerabilities in IBM InfoSphere Information Server
- Multiple vulnerabilities in IBM Business Automation Insights
- Multiple vulnerabilities in IBM Business Automation Workflow
- Multiple vulnerabilities in IBM MQ Operator and Queue manager container images
- Multiple vulnerabilities in IBM CICS Transaction Gateway Desktop Edition and CICS Transaction Gateway for Multiplatforms
- Multiple vulnerabilities in IBM Tivoli Application Dependency Discovery Manager
- Allocation of Resources Without Limits or Throttling in IBM Storage Protect Operations Center
- Allocation of resources without limits or throttling in IBM Maximo Application Suite - Manage Component
- IBM Maximo Application Suite - Monitor Component update for WebSphere Application Server Liberty
- Multiple vulnerabilities in IBM Verify Identity Access and IBM Security Verify Access
- Multiple vulnerabilities in IBM Sterling Partner Engagement Manager Essentials Edition
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM Spectrum Symphony
- Allocation of resources without limits or throttling in IBM Watson Discovery Cartridge
- Multiple vulnerabilities in IBM Security Directory Suite
- Multiple vulnerabilities in IBM Security Verify Directory
- Multiple vulnerabilities in IBM Operations Analytics - Log Analysis
- Multiple vulnerabilities in IBM Storage Protect Backup-Archive Client, IBM Storage Protect for Virtual Environments and IBM Storage Protect for Space Management
- Multiple vulnerabilities in IBM Application Performance Management