CVE-2025-36097
IBM WebSphere Application Server vulnerability analysis and mitigation

Overview

CVE-2025-36097 is a denial-of-service vulnerability in IBM WebSphere Application Server (WAS) and WebSphere Application Server Liberty caused by a stack-based buffer overflow (CWE-121). Affected versions include IBM WebSphere Application Server 9.0 (all builds prior to 9.0.5.24) and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7. The vulnerability was published on July 16, 2025, and patches were made available by August 2025. It carries a CVSS v3.1 base score of 7.5 (High) (IBM Advisory, Red Hat CVE).

Technical details

The root cause is a stack-based buffer overflow (CWE-121) in the request-handling logic of IBM WebSphere Application Server and its Liberty variant. An unauthenticated remote attacker can send a specially crafted network request that triggers the overflow, causing the server to consume excessive memory resources. No authentication or user interaction is required, and the attack complexity is low, making it straightforward to trigger remotely over the network (IBM Advisory).

Impact

Successful exploitation results in a denial-of-service condition, causing the affected WebSphere Application Server or Liberty instance to consume excessive memory and potentially become unresponsive. There is no impact on confidentiality or integrity — the vulnerability is limited to availability. Organizations relying on WAS or Liberty for critical application hosting may experience service outages affecting end users and dependent systems (IBM Advisory, Red Hat CVE).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2025-36097 as of the available data. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.039%, indicating a low probability of exploitation in the near term. The vulnerability is detectable by Qualys (QIDs 383599, 383600, 385652) and Nessus (plugin 242285) (IBM Advisory, Tenable).

Mitigation and workarounds

IBM has released patched versions to address this vulnerability: WebSphere Application Server 9.0 users should upgrade to fix pack 9.0.5.24 or later, and WebSphere Application Server Liberty users should upgrade to version 25.0.0.8 or later. The Open Liberty 25.0.0.8 release (August 12, 2025) also includes the fix. IBM Application Performance Management products that bundle WAS or Liberty are also affected and have a separate advisory. Organizations should apply the relevant fix pack as soon as possible and consult the IBM security bulletin for interim fixes if immediate upgrade is not feasible (IBM Advisory, IBM APM Advisory, Open Liberty Blog).

Community reactions

The vulnerability received routine coverage from vulnerability tracking services and security aggregators shortly after disclosure on July 16, 2025. CISA included it in its weekly vulnerability bulletin (SB25-202) for the week of July 14, 2025. RedPacket Security and other community aggregators shared alerts via social media. No notable independent researcher commentary or significant media coverage beyond standard advisory distribution has been identified (CISA Bulletin, RedPacket Security).

Additional resources


SourceThis report was generated using AI

Related IBM WebSphere Application Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-8400CRITICAL9.8
  • IBM JDK logoIBM JDK
  • java-1_8_0-ibm-src
NoYesAug 05, 2026
CVE-2026-14525CRITICAL9.4
  • IBM WebSphere Application Server logoIBM WebSphere Application Server
  • cpe:2.3:a:ibm:websphere_application_server
NoYesAug 13, 2026
CVE-2026-11536HIGH8.5
  • IBM WebSphere Application Server logoIBM WebSphere Application Server
  • cpe:2.3:a:ibm:websphere_application_server
NoYesJul 30, 2026
CVE-2026-18499HIGH8.1
  • IBM WebSphere Application Server logoIBM WebSphere Application Server
  • cpe:2.3:a:ibm:websphere_application_server
NoYesAug 12, 2026
CVE-2026-10571MEDIUM5.3
  • IBM WebSphere Application Server logoIBM WebSphere Application Server
  • cpe:2.3:a:ibm:websphere_application_server
NoYesAug 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management