CVE-2025-36038
IBM WebSphere Application Server vulnerability analysis and mitigation

Overview

CVE-2025-36038 is a critical deserialization vulnerability in IBM WebSphere Application Server (WAS) that allows unauthenticated remote attackers to execute arbitrary code by sending a specially crafted sequence of serialized objects. It affects WAS versions 8.5 through 8.5.5.27 and 9.0 through 9.0.5.24. The vulnerability was published on June 25, 2025, with patches released by IBM. It carries a CVSS v3.1 base score of 9.8 (Critical) (IBM Advisory, Feedly).

Technical details

The root cause is improper deserialization of untrusted data (CWE-502), mapped to CAPEC-586 (Object Injection). An attacker can exploit this by sending a specially crafted sequence of serialized Java objects to the WAS endpoint over the network, triggering arbitrary code execution without requiring authentication or user interaction. The attack vector is network-based with low complexity and no privileges required, making it trivially exploitable from remote locations (IBM Advisory, Feedly).

Impact

Successful exploitation results in complete compromise of the affected WebSphere Application Server instance, with high impact to confidentiality, integrity, and availability. An attacker can execute arbitrary code as the WAS service account, enabling unauthorized data access, system manipulation, deployment of malware or backdoors, and potential lateral movement within the enterprise network. Given WAS is commonly used in enterprise Java EE environments, exploitation could expose sensitive business data and disrupt critical application services (IBM Advisory, GBHackers).

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit code and no confirmed evidence of active in-the-wild exploitation (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.244%, indicating a currently low but non-negligible probability of exploitation in the near term. Detection plugins are available from Qualys (ID: 383423) and Nessus (ID: 240709), and DIVD CSIRT has opened a case (DIVD-2025-00034) to notify potentially affected organizations (DIVD CSIRT, Tenable).

Exploitation steps

  1. Reconnaissance: Identify internet-facing IBM WebSphere Application Server instances running versions 8.5.x below 8.5.5.28 or 9.0.x below 9.0.5.25 using tools such as Shodan, Censys, or FOFA, targeting default WAS ports (e.g., 9080, 9443, 8880).
  2. Craft malicious payload: Construct a specially crafted sequence of serialized Java objects designed to exploit the deserialization vulnerability in WAS. Tools such as ysoserial can be used to generate gadget chains compatible with the WAS classpath.
  3. Deliver payload: Transmit the malicious serialized object sequence to the vulnerable WAS endpoint (e.g., via the IIOP or HTTP/SOAP interface) without requiring authentication credentials.
  4. Achieve code execution: The WAS server deserializes the malicious object, triggering execution of attacker-controlled code as the WAS service account, enabling reverse shell establishment, data exfiltration, or further lateral movement within the network (IBM Advisory, NSFocus).

Indicators of compromise

  • Network: Unexpected inbound connections to WAS ports (9080, 9443, 8880, 2809) from external or untrusted IP addresses; anomalous outbound connections from the WAS server to unknown external hosts (potential reverse shell or C2 traffic).
  • Logs: WAS system logs (SystemOut.log, SystemErr.log) showing Java deserialization errors or unexpected class loading events; access logs with unusual or malformed request bodies targeting WAS endpoints.
  • Process: Unexpected child processes spawned by the WAS JVM process (e.g., cmd.exe, /bin/bash, powershell.exe, curl, wget); unusual process activity under the WAS service account.
  • File System: New or modified files in the WAS installation directory, including unexpected web shells, scripts, or JAR files; new scheduled tasks or cron jobs created by the WAS service account.
  • Registry (Windows): New or modified registry run keys associated with the WAS service account indicating persistence mechanisms.

Mitigation and workarounds

IBM has released patched versions to address this vulnerability: upgrade WebSphere Application Server 8.5.x to version 8.5.5.28 or later, and WAS 9.0.x to version 9.0.5.25 or later (IBM Advisory). As interim workarounds, implement network-level access controls (firewalls, ACLs) to restrict access to WAS ports from untrusted networks, and monitor for suspicious deserialization activity in WAS logs. Patching is the strongly recommended remediation given the critical severity and unauthenticated attack vector.

Community reactions

IBM published an official security bulletin on June 30, 2025, confirming the vulnerability and providing patch guidance (IBM Advisory). Security media outlets including GBHackers, Heise, and SecurityOnline covered the disclosure, highlighting the critical unauthenticated RCE nature of the flaw (GBHackers, Heise, SecurityOnline). DIVD CSIRT opened case DIVD-2025-00034 to proactively notify affected organizations, and the Western Australian Government SOC issued an advisory on July 17, 2025 (DIVD CSIRT, WA Gov SOC). Community discussion on Mastodon and Bluesky noted the severity and urged prompt patching.

Additional resources


SourceThis report was generated using AI

Related IBM WebSphere Application Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-14980HIGH8.8
  • IBM WebSphere Application Server logoIBM WebSphere Application Server
  • cpe:2.3:a:ibm:websphere_application_server
NoYesJul 30, 2026
CVE-2026-11536HIGH8.5
  • IBM WebSphere Application Server logoIBM WebSphere Application Server
  • cpe:2.3:a:ibm:websphere_application_server
NoYesJul 30, 2026
CVE-2026-8400HIGH8.1
  • IBM JDK logoIBM JDK
  • java-1.8.0-ibm-src
NoYesAug 05, 2026
CVE-2026-9322HIGH7.5
  • IBM WebSphere Application Server logoIBM WebSphere Application Server
  • cpe:2.3:a:ibm:websphere_application_server
NoYesJul 30, 2026
CVE-2026-10842HIGH7.5
  • IBM WebSphere Application Server logoIBM WebSphere Application Server
  • cpe:2.3:a:ibm:websphere_application_server
NoYesJul 30, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management