Resource exhaustion in qs - CVE-2025-15284

 

Resource exhaustion in qs - CVE-2025-15284

Published: January 12, 2026 / Updated: January 14, 2026


Vulnerability identifier: #VU121159
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-15284
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to the arrayLimit option does not enforce limits for bracket notation (a[]=1&a[]=2). A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

qs
Storage Sentinel Anomaly Scan Engine
Rhapsody Systems Engineering
Guardium Data Security Center (GDSC)
Security QRadar EDR
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component
watsonx Code Assistant On Prem
Db2 Big SQL
Maximo Application Suite - Monitor Component
Maximo Application Suite Ai Service
Maximo Application Suite - Reliability Strategies
Rational Performance Tester
DevOps Test Performance
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
Data Cataloging
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
watsonx Assistant Cartridge
MongoDB Enterprise Advanced with IBM
InfoSphere Optim Archive Viewer
Developer Hub
IBM App Connect Enterprise
Planning Analytics Local
IBM Fusion HCI
PowerVC
Splunk DB Connect
Automation Assets in IBM Cloud Pak for Integration (CP4I)
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Sterling Secure Proxy
IBM Sterling External Authentication Server
Jira Service Management Server
Jira Service Management Data Center
Jira Software Data Center
AppDynamics NodeJS Agent
App Connect Enterprise Certified Container
Communications Unified Assurance
nest
Event Streams
Jira Software Server
IBM DataPower Gateway
Red Hat OpenShift Container Platform
IBM InfoSphere Information Server
Fedora
linux-sgx
OpenShift Data Foundation (formerly OpenShift Container Storage)

How to mitigate CVE-2025-15284

Install updates from vendor's website.

qs - update to 6.14.1
Storage Sentinel Anomaly Scan Engine - update to 2.3.0
Rhapsody Systems Engineering - addressed in versions 1.5.5, 1.6.1
Developer Hub - addressed in versions 1.7.4, 1.8.2
Planning Analytics Local - update to 2.1.18
IBM Fusion HCI - update to 2.12.2
Splunk DB Connect - update to 4.2.0
Guardium Data Security Center (GDSC) - update to 3.8.8
Security QRadar EDR - update to 3.12.24
Automation Assets in IBM Cloud Pak for Integration (CP4I) - addressed in versions 4.0.22-sc2, 4.3.5
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.1
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component - update to 5.3.1
watsonx Code Assistant On Prem - update to 5.3.1
IBM Sterling Secure Proxy - addressed in versions 6.1.0.3, 6.2.0.3, 6.2.1.1
IBM Sterling External Authentication Server - addressed in versions 6.1.0.4, 6.1.1.1
Db2 Big SQL - update to 8.3.1
Maximo Application Suite - Monitor Component - addressed in versions 8.10.28, 8.11.26, 9.0.18, 9.1.8
Maximo Application Suite Ai Service - update to 9.1.11
Maximo Application Suite - Reliability Strategies - update to 9.1.177
nest - update to 10.4.21
Event Streams - update to 12.2.2
Jira Service Management Server - update to 10.3.16
Jira Service Management Data Center - update to 10.3.16
Jira Software Server - update to 10.3.15
Jira Software Data Center - update to 10.3.15
IBM DataPower Gateway - addressed in versions 10.5.0.21, 10.6.0.9, 11.0.0.0
DevOps Test Performance - update to 11.0.8
IBM InfoSphere Information Server - update to 11.7.1.6 Service pack 2
IBM App Connect Enterprise - addressed in versions 12.0.12.22, 13.0.6.1
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 16.1.0.25, 16.1.3.6
AppDynamics NodeJS Agent - update to 25.12.1
Data Cataloging - update to 2.5.2
linux-sgx - update to 2.26-34.fc43
Red Hat OpenShift Container Platform - update to 4.17.55
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.18.25, 4.19.20
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.4
watsonx Assistant Cartridge - update to 5.4
MongoDB Enterprise Advanced with IBM - update to 8.0.19
InfoSphere Optim Archive Viewer - update to 11.7.0.14
App Connect Enterprise Certified Container - addressed in versions 12.0.21, 12.21.0

External References

Related Security Bulletins