CRITICAL🇵🇱 Wersja polska

CVE-2025-36038

CVSS 9.0v3.1pub. 2025-06-25upd. 2025-07-18

IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence of serialized objects.

🤖 AI Analysis
How it works

The vulnerability results from unsafe processing of serialized Java objects (CWE-502 — deserialization of untrusted data). An attacker remotely sends a specially crafted sequence of serialized objects, which when processed by the server leads to arbitrary code execution. The attack does not require authentication or user interaction, however it requires a certain degree of complexity on the attacker's side (AC:H).

Impact

Successful exploitation of this vulnerability allows a remote attacker to execute arbitrary code on the server with the privileges of the IBM WebSphere process, which may result in complete system compromise, breach of confidentiality, integrity, and availability of data.

Mitigation & patch

Apply patches available from the vendor according to the references — details available at: https://www.ibm.com/support/pages/node/7237967

Who is affected

IBM WebSphere Application Server 8.5 and 9.0 running on HP-UX, Linux, IBM z/OS, and IBM AIX systems

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
  • HP Ux

    OS
    Hp
    all versions
  • IBM Aix

    OS
    Ibm
    all versions
  • IBM I

    OS
    Ibm
    all versions
  • IBM Websphere Application Server

    APP
    Ibm
    8.5 – 8.5.5.28 (excl.)9.0 – 9.0.5.25 (excl.)
  • IBM Z\/os

    OS
    Ibm
    all versions
  • Linux Kernel

    OS
    Linux
    all versions
  • Microsoft Windows

    OS
    Microsoft
    all versions
  • Oracle Solaris

    OS
    Oracle
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEDeserialization
CWE
References

Related vulnerabilities

CVE-2026-8398CRITICAL9.3⚠ KEVPL ✓same product

Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów

CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product

Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty

CVE-2025-34028CRITICAL9.3⚠ KEVPL ✓same product

Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP

CVE-2024-7262CRITICAL9.3⚠ KEVPL ✓same product

Path Traversal w Kingsoft WPS Office — ładowanie dowolnej biblioteki Windows

CVE-2024-4577CRITICAL9.8⚠ KEVPL ✓same product

PHP CGI argument injection – RCE na Windows przez mechanizm Best-Fit