Denial of Service Vulnerability in IBM WebSphere Application Server
CVE-2025-36099

4.9MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
29 September 2025

What is CVE-2025-36099?

IBM WebSphere Application Server versions 8.5 and 9.0 are susceptible to a denial of service attack due to the acceptance of specially-crafted requests. This vulnerability allows privileged users to exploit the system, leading the server to consume excessive memory resources, thereby affecting its performance and availability.

Affected Version(s)

WebSphere Application Server 8.5

WebSphere Application Server 9.0

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.