IBM WebSphere Application Server Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in IBM WebSphere Application Server versions 8.5 and 9.0. This vulnerability allows a privileged user to send a specially-crafted request that causes the server to consume excessive memory resources, potentially leading to degraded performance or service disruption.

Impact

Exploitation of this vulnerability can cause the server to consume large amounts of memory, leading to performance degradation or service disruption.

Remediation

Users are advised to upgrade to IBM WebSphere Application Server Fix Pack 9.0.5.26 or later, or Fix Pack 8.5.5.29 or later. Interim fixes resolving this vulnerability are also available. Additional interim fixes may be linked off the interim fix download page.

Added: Sep 29, 2025, 7:25 PM
Updated: Sep 29, 2025, 7:44 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
2.5
exploitability
5.0
remediation
7.7
relevance
0.6
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.