
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-36038 is a critical deserialization vulnerability in IBM WebSphere Application Server (WAS) that allows unauthenticated remote attackers to execute arbitrary code by sending a specially crafted sequence of serialized objects. It affects WAS versions 8.5 through 8.5.5.27 and 9.0 through 9.0.5.24. The vulnerability was published on June 25, 2025, with patches released by IBM. It carries a CVSS v3.1 base score of 9.8 (Critical) (IBM Advisory, Feedly).
The root cause is improper deserialization of untrusted data (CWE-502), mapped to CAPEC-586 (Object Injection). An attacker can exploit this by sending a specially crafted sequence of serialized Java objects to the WAS endpoint over the network, triggering arbitrary code execution without requiring authentication or user interaction. The attack vector is network-based with low complexity and no privileges required, making it trivially exploitable from remote locations (IBM Advisory, Feedly).
Successful exploitation results in complete compromise of the affected WebSphere Application Server instance, with high impact to confidentiality, integrity, and availability. An attacker can execute arbitrary code as the WAS service account, enabling unauthorized data access, system manipulation, deployment of malware or backdoors, and potential lateral movement within the enterprise network. Given WAS is commonly used in enterprise Java EE environments, exploitation could expose sensitive business data and disrupt critical application services (IBM Advisory, GBHackers).
As of the time of reporting, there is no public proof-of-concept exploit code and no confirmed evidence of active in-the-wild exploitation (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.244%, indicating a currently low but non-negligible probability of exploitation in the near term. Detection plugins are available from Qualys (ID: 383423) and Nessus (ID: 240709), and DIVD CSIRT has opened a case (DIVD-2025-00034) to notify potentially affected organizations (DIVD CSIRT, Tenable).
SystemOut.log, SystemErr.log) showing Java deserialization errors or unexpected class loading events; access logs with unusual or malformed request bodies targeting WAS endpoints.cmd.exe, /bin/bash, powershell.exe, curl, wget); unusual process activity under the WAS service account.IBM has released patched versions to address this vulnerability: upgrade WebSphere Application Server 8.5.x to version 8.5.5.28 or later, and WAS 9.0.x to version 9.0.5.25 or later (IBM Advisory). As interim workarounds, implement network-level access controls (firewalls, ACLs) to restrict access to WAS ports from untrusted networks, and monitor for suspicious deserialization activity in WAS logs. Patching is the strongly recommended remediation given the critical severity and unauthenticated attack vector.
IBM published an official security bulletin on June 30, 2025, confirming the vulnerability and providing patch guidance (IBM Advisory). Security media outlets including GBHackers, Heise, and SecurityOnline covered the disclosure, highlighting the critical unauthenticated RCE nature of the flaw (GBHackers, Heise, SecurityOnline). DIVD CSIRT opened case DIVD-2025-00034 to proactively notify affected organizations, and the Western Australian Government SOC issued an advisory on July 17, 2025 (DIVD CSIRT, WA Gov SOC). Community discussion on Mastodon and Bluesky noted the severity and urged prompt patching.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."