Resource exhaustion in qs - CVE-2025-15284
Published: January 12, 2026 / Updated: January 14, 2026
Vulnerability identifier: #VU121159
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-15284
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to the arrayLimit option does not enforce limits for bracket notation (a[]=1&a[]=2). A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
qs
Storage Sentinel Anomaly Scan Engine
Rhapsody Systems Engineering
Guardium Data Security Center (GDSC)
Security QRadar EDR
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component
watsonx Code Assistant On Prem
Db2 Big SQL
Maximo Application Suite - Monitor Component
Maximo Application Suite Ai Service
Maximo Application Suite - Reliability Strategies
Rational Performance Tester
DevOps Test Performance
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
Data Cataloging
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
watsonx Assistant Cartridge
MongoDB Enterprise Advanced with IBM
InfoSphere Optim Archive Viewer
Developer Hub
IBM App Connect Enterprise
Planning Analytics Local
IBM Fusion HCI
PowerVC
Splunk DB Connect
Automation Assets in IBM Cloud Pak for Integration (CP4I)
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Sterling Secure Proxy
IBM Sterling External Authentication Server
Jira Service Management Server
Jira Service Management Data Center
Jira Software Data Center
AppDynamics NodeJS Agent
App Connect Enterprise Certified Container
Communications Unified Assurance
nest
Event Streams
Jira Software Server
IBM DataPower Gateway
Red Hat OpenShift Container Platform
IBM InfoSphere Information Server
Fedora
linux-sgx
OpenShift Data Foundation (formerly OpenShift Container Storage)
Storage Sentinel Anomaly Scan Engine
Rhapsody Systems Engineering
Guardium Data Security Center (GDSC)
Security QRadar EDR
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component
watsonx Code Assistant On Prem
Db2 Big SQL
Maximo Application Suite - Monitor Component
Maximo Application Suite Ai Service
Maximo Application Suite - Reliability Strategies
Rational Performance Tester
DevOps Test Performance
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
Data Cataloging
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
watsonx Assistant Cartridge
MongoDB Enterprise Advanced with IBM
InfoSphere Optim Archive Viewer
Developer Hub
IBM App Connect Enterprise
Planning Analytics Local
IBM Fusion HCI
PowerVC
Splunk DB Connect
Automation Assets in IBM Cloud Pak for Integration (CP4I)
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Sterling Secure Proxy
IBM Sterling External Authentication Server
Jira Service Management Server
Jira Service Management Data Center
Jira Software Data Center
AppDynamics NodeJS Agent
App Connect Enterprise Certified Container
Communications Unified Assurance
nest
Event Streams
Jira Software Server
IBM DataPower Gateway
Red Hat OpenShift Container Platform
IBM InfoSphere Information Server
Fedora
linux-sgx
OpenShift Data Foundation (formerly OpenShift Container Storage)
How to mitigate CVE-2025-15284
Install updates from vendor's website.
qs - update to 6.14.1
Storage Sentinel Anomaly Scan Engine - update to 2.3.0
Rhapsody Systems Engineering - addressed in versions 1.5.5, 1.6.1
Developer Hub - addressed in versions 1.7.4, 1.8.2
Planning Analytics Local - update to 2.1.18
IBM Fusion HCI - update to 2.12.2
Splunk DB Connect - update to 4.2.0
Guardium Data Security Center (GDSC) - update to 3.8.8
Security QRadar EDR - update to 3.12.24
Automation Assets in IBM Cloud Pak for Integration (CP4I) - addressed in versions 4.0.22-sc2, 4.3.5
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.1
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component - update to 5.3.1
watsonx Code Assistant On Prem - update to 5.3.1
IBM Sterling Secure Proxy - addressed in versions 6.1.0.3, 6.2.0.3, 6.2.1.1
IBM Sterling External Authentication Server - addressed in versions 6.1.0.4, 6.1.1.1
Db2 Big SQL - update to 8.3.1
Maximo Application Suite - Monitor Component - addressed in versions 8.10.28, 8.11.26, 9.0.18, 9.1.8
Maximo Application Suite Ai Service - update to 9.1.11
Maximo Application Suite - Reliability Strategies - update to 9.1.177
nest - update to 10.4.21
Event Streams - update to 12.2.2
Jira Service Management Server - update to 10.3.16
Jira Service Management Data Center - update to 10.3.16
Jira Software Server - update to 10.3.15
Jira Software Data Center - update to 10.3.15
IBM DataPower Gateway - addressed in versions 10.5.0.21, 10.6.0.9, 11.0.0.0
DevOps Test Performance - update to 11.0.8
IBM InfoSphere Information Server - update to 11.7.1.6 Service pack 2
IBM App Connect Enterprise - addressed in versions 12.0.12.22, 13.0.6.1
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 16.1.0.25, 16.1.3.6
AppDynamics NodeJS Agent - update to 25.12.1
Data Cataloging - update to 2.5.2
linux-sgx - update to 2.26-34.fc43
Red Hat OpenShift Container Platform - update to 4.17.55
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.18.25, 4.19.20
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.4
watsonx Assistant Cartridge - update to 5.4
MongoDB Enterprise Advanced with IBM - update to 8.0.19
InfoSphere Optim Archive Viewer - update to 11.7.0.14
App Connect Enterprise Certified Container - addressed in versions 12.0.21, 12.21.0
Storage Sentinel Anomaly Scan Engine - update to 2.3.0
Rhapsody Systems Engineering - addressed in versions 1.5.5, 1.6.1
Developer Hub - addressed in versions 1.7.4, 1.8.2
Planning Analytics Local - update to 2.1.18
IBM Fusion HCI - update to 2.12.2
Splunk DB Connect - update to 4.2.0
Guardium Data Security Center (GDSC) - update to 3.8.8
Security QRadar EDR - update to 3.12.24
Automation Assets in IBM Cloud Pak for Integration (CP4I) - addressed in versions 4.0.22-sc2, 4.3.5
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.1
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component - update to 5.3.1
watsonx Code Assistant On Prem - update to 5.3.1
IBM Sterling Secure Proxy - addressed in versions 6.1.0.3, 6.2.0.3, 6.2.1.1
IBM Sterling External Authentication Server - addressed in versions 6.1.0.4, 6.1.1.1
Db2 Big SQL - update to 8.3.1
Maximo Application Suite - Monitor Component - addressed in versions 8.10.28, 8.11.26, 9.0.18, 9.1.8
Maximo Application Suite Ai Service - update to 9.1.11
Maximo Application Suite - Reliability Strategies - update to 9.1.177
nest - update to 10.4.21
Event Streams - update to 12.2.2
Jira Service Management Server - update to 10.3.16
Jira Service Management Data Center - update to 10.3.16
Jira Software Server - update to 10.3.15
Jira Software Data Center - update to 10.3.15
IBM DataPower Gateway - addressed in versions 10.5.0.21, 10.6.0.9, 11.0.0.0
DevOps Test Performance - update to 11.0.8
IBM InfoSphere Information Server - update to 11.7.1.6 Service pack 2
IBM App Connect Enterprise - addressed in versions 12.0.12.22, 13.0.6.1
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 16.1.0.25, 16.1.3.6
AppDynamics NodeJS Agent - update to 25.12.1
Data Cataloging - update to 2.5.2
linux-sgx - update to 2.26-34.fc43
Red Hat OpenShift Container Platform - update to 4.17.55
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.18.25, 4.19.20
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.4
watsonx Assistant Cartridge - update to 5.4
MongoDB Enterprise Advanced with IBM - update to 8.0.19
InfoSphere Optim Archive Viewer - update to 11.7.0.14
App Connect Enterprise Certified Container - addressed in versions 12.0.21, 12.21.0
External References
Related Security Bulletins
- Remote denial of service in qs
- Nest update for qs
- Multiple vulnerabilities in Red Hat Developer Hub 1.8
- Jira Service Management Data Center and Server update for qs
- Jira Software Data Center and Server update for qs
- IBM PowerVC update for qs parse module
- Fedora 43 update for linux-sgx
- IBM Maximo Application Suite - Reliability Strategies update for library qs
- IBM App Connect Enterprise update for node module qs
- Multiple vulnerabilities in IBM Maximo AI Service
- Multiple vulnerabilities in Red Hat Developer Hub 1.7
- Multiple vulnerabilities in IBM Sterling External Authentication Server
- Splunk DB Connect update for third-party components
- Multiple vulnerabilities in IBM Security QRadar EDR
- MongoDB Enterprise Advanced with IBM update for qs
- Multiple vulnerabilities in IBM Sterling Secure Proxy
- IBM Watson Discovery Cartridge update for qs
- IBM Maximo Application Suite - Monitor Component update for qs
- IBM Db2 Big SQL on Cloud Pak for Data update for qs
- Multiple vulnerabilities in IBM App Connect Enterprise Certified Container operands
- Multiple vulnerabilities in IBM watsonx Code Assistant On Prem
- Multiple vulnerabilities in IBM Event Streams
- Splunk AppDynamics NodeJS Agent update for third-party components
- IBM Rhapsody Systems Engineering update for qs
- Multiple vulnerabilities in IBM Planning Analytics Local
- IBM watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component update for qs
- IBM InfoSphere Information Server update for qs
- IBM DataPower Gateway update for qs
- Multiple vulnerabilities in IBM Guardium Data Security Center
- Multiple vulnerabilities in IBM DevOps Test Performance
- Multiple vulnerabilities in IBM Storage Sentinel Anomaly Scan Engine
- Multiple vulnerabilities in Communications Unified Assurance
- IBM Fusion, IBM Fusion HCI and IBM Fusion Data Cataloging update for qs
- Multiple vulnerabilities in IBM InfoSphere Optim Archive Viewer
- IBM watsonx Assistant Cartridge and IBM watsonx Orchestrate with watsonx Assistant Cartridge update for qs
- Multiple vulnerabilities in Platform Navigator and Automation Assets in IBM Cloud Pak for Integration
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.18
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.19
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17