Description

A dangerous security flaw called CVE-2025-36038 in IBM WebSphere Application Server lets unauthenticated attackers run harmful code on affected systems (versions 8.5 and 9.0), earning a very high CVSS score of 9.0 and requiring urgent fixes. A vulnerability in IBM WebSphere Application Server allows remote attackers to execute arbitrary code by exploiting the deserialization of untrusted data (CWE-502). This issue, identified as CVE-2025-36038, affects versions 8.5 and 9.0. By sending specially designed serialized objects, attackers can take control of the server without needing to log in. This can cause data leaks, service outages, and other serious problems. Although the attack is difficult to carry out (AC:H), it has a severe impact on confidentiality, integrity, and availability (C:H/I:H/A:H), making it a top security concern. IBM WebSphere Application Server 9.0. IBM WebSphere Application Server 8.5. WebSphere Service Registry and Repository 8.5. For versions 9.0.0.0 to 9.0.5.24, update to the necessary fix pack and install the interim fix for APAR PH66674, or upgrade to Fix Pack 9.0.5.25 or newer (planned for Q3 2025). For systems running versions 8.5.0.0 through 8.5.5.27, apply the fix pack and interim fix associated with APAR PH66674, or upgrade to Fix Pack 8.5.5.28 or later, which is expected to be released in Q3 2025. The critical CVE-2025-36038 flaw exposes organizations to significant risk until it is fixed with patches. Security experts recommend immediate action to prevent exploitation. Organizations should monitor IBM’s security bulletins for updates and act quickly to protect their systems.