High Severity Vulnerability
This vulnerability has been rated as High severity. Immediate action is recommended.
CVE-2025-36097
HighVulnerability Description
IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 are vulnerable to a denial of service, caused by a stack-based overflow. An attacker can send a specially crafted request that cause the server to consume excessive memory resources.
CVSS Metrics
Common Vulnerability Scoring System
Vector String:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Known Affected Software
70 configuration(s) from 1 vendor(s)
cpe:2.3:a:ibm:websphere_application_server:21.0.0.10:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.0.0:*:*:*:traditional:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.5.15:*:*:*:-:*:*:*
cpe:2.3:a:ibm:websphere_application_server:21.0.0.2:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:websphere_application_server:19.0.0.11:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:websphere_application_server:20.0.0.2:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:websphere_application_server:19.0.0.7:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.0.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.0.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:20.0.0.4:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:websphere_application_server:24.0.0.4:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:websphere_application_server:20.0.0.5:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:21.0.0.3:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:websphere_application_server:19.0.0.5:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:websphere_application_server:19.0.0.1:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.0.6:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:17.0.0.4:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.5.8:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:19.0.0.6:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.0.11:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:20.0.0.6:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:websphere_application_server:19.0.0.2:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:websphere_application_server:21.0.0.12:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:websphere_application_server:19.0.0.3:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:17.0.0.3:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:websphere_application_server:20.0.0.7:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.5.5:*:*:*:hypervisor:*:*:*
cpe:2.3:a:ibm:websphere_application_server:24.0.0.3:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.5.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:22.0.0.5:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:websphere_application_server:24.0.0.6:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:websphere_application_server:20.0.0.1:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.0.7:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:21.0.0.1:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:websphere_application_server:19.0.0.12:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:websphere_application_server:23.0.0.3:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.5.7:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:22.0.0.6:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:websphere_application_server:20.0.0.9:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.5.6:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.0.8:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:21.0.0.5:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:websphere_application_server:19.0.0.9:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.0.10:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:18.0.0.3:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:websphere_application_server:19.0.0.8:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:websphere_application_server:18.0.0.2:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.5.1:*:*:*:-:*:*:*
cpe:2.3:a:ibm:websphere_application_server:19.0.0.10:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:websphere_application_server:20.0.0.8:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:websphere_application_server:20.0.0.12:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:websphere_application_server:20.0.0.10:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:websphere_application_server:24.0.0.5:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:websphere_application_server:18.0.0.1:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.5.16:*:*:*:-:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.5.19:*:*:*:traditional:*:*:*
cpe:2.3:a:ibm:websphere_application_server:22.0.0.1:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:19.0.0.4:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:websphere_application_server:20.0.0.3:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.5.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.5.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:18.0.0.4:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.0.9:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:21.0.0.4:*:*:*:liberty:*:*:*
cpe:2.3:a:ibm:websphere_application_server:20.0.0.11:*:*:*:liberty:*:*:*
References & Resources
Severity Details
Weakness Type (CWE)
Stack-based Buffer Overflow
- Description
- A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
- Exploit Likelihood
- High
- Typical Severity
- High
- Abstraction Level
- Variant
Key Information
- Published Date
- July 16, 2025
