We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-36097

IBM WebSphere Application Server denial of service



Description

IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 are vulnerable to a denial of service, caused by a stack-based overflow. An attacker can send a specially crafted request that cause the server to consume excessive memory resources.

Reserved 2025-04-15 | Published 2025-07-16 | Updated 2025-07-17 | Assigner ibm


HIGH: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Problem types

CWE-121 Stack-based Buffer Overflow

Product status

Default status
unaffected

9.0
affected

Default status
unaffected

17.0.0.3
affected

References

www.ibm.com/support/pages/node/7239856 vendor-advisory

cve.org (CVE-2025-36097)

nvd.nist.gov (CVE-2025-36097)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-36097

Support options

Helpdesk Chat, Email, Knowledgebase