CVE-2025-36128

IBM MQ 9.1, 9.2, 9.3, 9.4 LTS and 9.3, 9.4 CD is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations. By conducting slowloris-type attacks, a remote attacker could exploit this vulnerability to cause a denial of service.
References
Link Resource
https://www.ibm.com/support/pages/node/7244480 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:ibm:mq:9.1.0.0:*:*:*:lts:*:*:*
cpe:2.3:a:ibm:mq:9.2.0.0:*:*:*:lts:*:*:*
cpe:2.3:a:ibm:mq:9.3.0:*:*:*:continuous_delivery:*:*:*
cpe:2.3:a:ibm:mq:9.3.0.0:*:*:*:lts:*:*:*
cpe:2.3:a:ibm:mq:9.4.0:*:*:*:continuous_delivery:*:*:*
cpe:2.3:a:ibm:mq:9.4.0.0:*:*:*:lts:*:*:*
OR cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:oracle:solaris:-:*:*:*:*:*:*:*

History

28 Oct 2025, 16:53

Type Values Removed Values Added
References () https://www.ibm.com/support/pages/node/7244480 - () https://www.ibm.com/support/pages/node/7244480 - Vendor Advisory
CPE cpe:2.3:a:ibm:mq:9.1.0.0:*:*:*:lts:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.0.0:*:*:*:lts:*:*:*
cpe:2.3:o:oracle:solaris:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.0:*:*:*:continuous_delivery:*:*:*
cpe:2.3:a:ibm:mq:9.2.0.0:*:*:*:lts:*:*:*
cpe:2.3:a:ibm:mq:9.3.0:*:*:*:continuous_delivery:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.0.0:*:*:*:lts:*:*:*
First Time Ibm aix
Linux
Oracle solaris
Microsoft windows
Linux linux Kernel
Oracle
Ibm i
Microsoft
Ibm
Ibm mq

16 Oct 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-16 17:15

Updated : 2025-10-28 16:53


NVD link : CVE-2025-36128

Mitre link : CVE-2025-36128

CVE.ORG link : CVE-2025-36128


JSON object : View

Products Affected

oracle

  • solaris

ibm

  • aix
  • i
  • mq

microsoft

  • windows

linux

  • linux_kernel
CWE
CWE-772

Missing Release of Resource after Effective Lifetime