CVE-2025-36128
IBM WebSphere MQ vulnerability analysis and mitigation

Overview

CVE-2025-36128 is a denial-of-service vulnerability in IBM MQ caused by improper enforcement of timeouts on individual read operations, making it susceptible to slowloris-type attacks. It affects IBM MQ versions 9.1, 9.2, 9.3, and 9.4 LTS, as well as 9.3 and 9.4 Continuous Delivery (CD) releases, across multiple operating systems including Linux, Windows, AIX, IBM i, and Oracle Solaris. The vulnerability was published on October 16, 2025, with initial NVD analysis completed on October 28, 2025. It carries a CVSS v3.1 base score of 7.5 (High), assigned by IBM Corporation (IBM Advisory, Red Hat CVE).

Technical details

The root cause is classified as CWE-772 (Missing Release of Resource after Effective Lifetime), where IBM MQ fails to properly enforce timeouts on individual read operations, allowing connections to be held open indefinitely. This enables a slowloris-style attack, where an attacker sends partial HTTP or protocol-level requests at a slow rate to exhaust available connection slots or resources without completing the transaction. No authentication, user interaction, or elevated privileges are required to exploit this vulnerability — only network access to the IBM MQ service. No public proof-of-concept code has been identified at this time (IBM Advisory, Red Hat CVE).

Impact

Successful exploitation results in a complete denial of service against the affected IBM MQ instance, with high availability impact and no confidentiality or integrity impact. A remote, unauthenticated attacker can disrupt message queuing services, potentially causing significant operational interruptions for enterprise applications and workflows that depend on IBM MQ for messaging. Given IBM MQ's role as critical middleware in many enterprise environments, prolonged service disruption could cascade to dependent business processes (IBM Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible IBM MQ instances running affected versions (9.1, 9.2, 9.3, 9.4 LTS or 9.3, 9.4 CD) using network scanning tools such as Nmap or Shodan, targeting default IBM MQ listener ports (e.g., TCP 1414).
  2. Initiate slowloris-style connections: Open multiple TCP connections to the IBM MQ listener port and send partial or incomplete protocol-level requests, deliberately sending data at an extremely slow rate to prevent the server from closing the connection.
  3. Sustain connection exhaustion: Maintain a large number of these slow, incomplete connections simultaneously. Because IBM MQ does not properly enforce read operation timeouts, these connections are not terminated, consuming available connection slots or thread pool resources.
  4. Achieve denial of service: As connection resources are exhausted, legitimate clients are unable to connect to or communicate with the IBM MQ service, resulting in a denial of service condition (IBM Advisory).

Indicators of compromise

  • Network: Unusually high number of long-lived, low-throughput TCP connections to IBM MQ listener ports (default TCP 1414); connections from a single or small set of source IPs that remain open without completing transactions.
  • Logs: IBM MQ error logs showing connection timeouts, resource exhaustion messages, or repeated failed connection completions; system logs indicating thread pool or socket exhaustion on the MQ host.
  • Process/System: Elevated number of open file descriptors or socket handles associated with the IBM MQ process (amqrmppa, runmqlsr); degraded or unresponsive MQ listener as observed via dspmq or runmqsc commands.
  • Availability: Legitimate MQ client applications reporting connection failures or timeouts to the IBM MQ queue manager during the attack window.

Mitigation and workarounds

IBM has released a patch addressing this vulnerability; administrators should apply the fix detailed in IBM support page node 7244480 for their respective MQ version and release track (LTS or CD). As interim mitigations, implement network-level controls to limit the number of concurrent connections per source IP to IBM MQ listener ports, and configure firewall or load balancer rules to detect and block slowloris-type connection patterns. Additionally, consider restricting network exposure of IBM MQ services to trusted networks or VPNs where possible, and monitor for anomalous connection behavior (IBM Advisory).

Additional resources


SourceThis report was generated using AI

Related IBM WebSphere MQ vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-36128HIGH7.5
  • IBM WebSphere MQ logoIBM WebSphere MQ
  • cpe:2.3:a:ibm:mq
NoYesOct 16, 2025
CVE-2025-36100MEDIUM5.5
  • IBM WebSphere MQ logoIBM WebSphere MQ
  • cpe:2.3:a:ibm:mq
NoYesSep 07, 2025
CVE-2025-0985MEDIUM5.5
  • IBM WebSphere MQ logoIBM WebSphere MQ
  • mq
NoYesFeb 28, 2025
CVE-2024-54175MEDIUM5.5
  • IBM WebSphere MQ logoIBM WebSphere MQ
  • cpe:2.3:a:ibm:mq
NoYesFeb 28, 2025
CVE-2026-1713MEDIUM5
  • IBM WebSphere MQ logoIBM WebSphere MQ
  • cpe:2.3:a:ibm:mq
NoYesMar 03, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management