Back

HIGH

IBM WebSphere Application Server denial of service

Published Jul 16, 2025

Description

IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 are vulnerable to a denial of service, caused by a stack-based overflow. An attacker can send a specially crafted request that cause the server to consume excessive memory resources.

Affected products

Remediation

Vendor solution

For IBM WebSphere Application Server Liberty 17.0.0.3 - 25.0.0.7 using the jsonp-1.0, jsonp-1.1, or jsonp-2.0 feature:

· Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves PH67183 --OR-- · Apply Fix Pack 25.0.0.8 or later (targeted availability 3Q2025).

For IBM WebSphere Application Server traditional:

For V9.0.0.0 through 9.0.5.24: · Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves PH67120 --OR-- · Apply Fix Pack 9.0.5.25 or later (targeted availability 3Q2025).

Additional interim fixes may be available and linked off the interim fix download page.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ibm
Published Jul 16, 2025
Updated Aug 18, 2025
Reserved Apr 15, 2025
CISA Vulnrichment
Updated Jul 18, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner ibm
Published Jul 16, 2025
Updated Aug 18, 2025
Exploited since n/a
EUVD-2025-21735