IBM WebSphere Application Server denial of service
Published Jul 16, 2025
7.5
HIGHCVSS 3.1
EPSS 0.46%
Description
IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 are vulnerable to a denial of service, caused by a stack-based overflow. An attacker can send a specially crafted request that cause the server to consume excessive memory resources.
Affected products
-
- Version 9.0StatusaffectedConstraints-
- Version
-
- Version 17.0.0.3StatusaffectedConstraints<=25.0.0.7
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| IBM | WebSphere Application Server | unaffected |
| ||||||
| IBM | WebSphere Application Server Liberty | unaffected |
|
- ≥ 9.0.0.0 · < 9.0.5.24
- ≥ 17.0.0.3 · < 25.0.0.8
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
For IBM WebSphere Application Server Liberty 17.0.0.3 - 25.0.0.7 using the jsonp-1.0, jsonp-1.1, or jsonp-2.0 feature:
· Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves PH67183 --OR-- · Apply Fix Pack 25.0.0.8 or later (targeted availability 3Q2025).
For IBM WebSphere Application Server traditional:
For V9.0.0.0 through 9.0.5.24: · Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves PH67120 --OR-- · Apply Fix Pack 9.0.5.25 or later (targeted availability 3Q2025).
Additional interim fixes may be available and linked off the interim fix download page.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-21735 Advisory
- https://www.ibm.com/support/pages/node/7239856 vendor-advisorypatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-21735 | Advisory | |
| https://www.ibm.com/support/pages/node/7239856 | vendor-advisorypatchVendor Advisory |
Change history (0)
No recorded changes yet.