
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-36128 is a denial-of-service vulnerability in IBM MQ caused by improper enforcement of timeouts on individual read operations, making it susceptible to slowloris-type attacks. It affects IBM MQ versions 9.1, 9.2, 9.3, and 9.4 LTS, as well as 9.3 and 9.4 Continuous Delivery (CD) releases, across multiple operating systems including Linux, Windows, AIX, IBM i, and Oracle Solaris. The vulnerability was published on October 16, 2025, with initial NVD analysis completed on October 28, 2025. It carries a CVSS v3.1 base score of 7.5 (High), assigned by IBM Corporation (IBM Advisory, Red Hat CVE).
The root cause is classified as CWE-772 (Missing Release of Resource after Effective Lifetime), where IBM MQ fails to properly enforce timeouts on individual read operations, allowing connections to be held open indefinitely. This enables a slowloris-style attack, where an attacker sends partial HTTP or protocol-level requests at a slow rate to exhaust available connection slots or resources without completing the transaction. No authentication, user interaction, or elevated privileges are required to exploit this vulnerability — only network access to the IBM MQ service. No public proof-of-concept code has been identified at this time (IBM Advisory, Red Hat CVE).
Successful exploitation results in a complete denial of service against the affected IBM MQ instance, with high availability impact and no confidentiality or integrity impact. A remote, unauthenticated attacker can disrupt message queuing services, potentially causing significant operational interruptions for enterprise applications and workflows that depend on IBM MQ for messaging. Given IBM MQ's role as critical middleware in many enterprise environments, prolonged service disruption could cascade to dependent business processes (IBM Advisory).
amqrmppa, runmqlsr); degraded or unresponsive MQ listener as observed via dspmq or runmqsc commands.IBM has released a patch addressing this vulnerability; administrators should apply the fix detailed in IBM support page node 7244480 for their respective MQ version and release track (LTS or CD). As interim mitigations, implement network-level controls to limit the number of concurrent connections per source IP to IBM MQ listener ports, and configure firewall or load balancer rules to detect and block slowloris-type connection patterns. Additionally, consider restricting network exposure of IBM MQ services to trusted networks or VPNs where possible, and monitor for anomalous connection behavior (IBM Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."