CVE-2025-1823: IBM Jazz Reporting Service Denial of Service

Published Feb 4, 2026
·
Updated

IBM Jazz Reporting Service could allow an authenticated user on the host network to cause a denial of service using specially crafted SQL query that consumes excess memory resources.

Affected Software

29 affected components
IBM Jazz Reporting Service
IBM Jazz Reporting Service=7.0.3
IBM Jazz Reporting Service=7.0.3-ifix001
IBM Jazz Reporting Service=7.0.3-ifix002
IBM Jazz Reporting Service=7.0.3-ifix003
IBM Jazz Reporting Service=7.0.3-ifix004
IBM Jazz Reporting Service=7.0.3-ifix005
IBM Jazz Reporting Service=7.0.3-ifix006
IBM Jazz Reporting Service=7.0.3-ifix007
IBM Jazz Reporting Service=7.0.3-ifix008
IBM Jazz Reporting Service=7.0.3-ifix009
IBM Jazz Reporting Service=7.0.3-ifix010
IBM Jazz Reporting Service=7.0.3-ifix011
IBM Jazz Reporting Service=7.0.3-ifix012
IBM Jazz Reporting Service=7.0.3-ifix013
IBM Jazz Reporting Service=7.0.3-ifix014
IBM Jazz Reporting Service=7.0.3-ifix015
IBM Jazz Reporting Service=7.0.3-ifix016
IBM Jazz Reporting Service=7.0.3-ifix017
IBM Jazz Reporting Service=7.0.3-ifix018
IBM Jazz Reporting Service=7.0.3-ifix019
IBM Jazz Reporting Service=7.0.3-ifix020
IBM Jazz Reporting Service=7.1
IBM Jazz Reporting Service=7.1-ifix001
IBM Jazz Reporting Service=7.1-ifix002
IBM Jazz Reporting Service=7.1-ifix003
IBM Jazz Reporting Service=7.1-ifix004-sr1-base
IBM Jazz Reporting Service=7.1-ifix005
IBM Jazz Reporting Service=7.1-ifix006

Remediation

Information

IBM strongly recommends addressing the vulnerability now by applying the iFix listed below: ProductVersioniFixRemediation / First FixIBM Jazz Reporting Service7.17.1iFix007 Fix Central - 7.1 https://www.ibm.com/support/fixcentral/swg/downloadFixes IBM Jazz Reporting Service7.0.37.0.3iFix021 Fix Central - 7.0.3 https://www.ibm.com/support/fixcentral/swg/doSelectFixes

Event History

Feb 4, 2026
CVE Published
via MITRE·09:07 PM
Data Sourced
via MITRE·09:07 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-1823?

CVE-2025-1823 is a denial of service vulnerability that can significantly impact the availability of the IBM Jazz Reporting Service.

2

How do I fix CVE-2025-1823?

To fix CVE-2025-1823, implement resource limits on SQL query execution and ensure regular monitoring of memory usage.

3

Who is affected by CVE-2025-1823?

CVE-2025-1823 affects organizations using IBM Jazz Reporting Service, especially in environments with authenticated users.

4

What causes CVE-2025-1823?

CVE-2025-1823 is caused by an authenticated user executing specially crafted SQL queries that consume excessive memory resources.

5

Can CVE-2025-1823 be exploited remotely?

CVE-2025-1823 requires an authenticated user on the host network to exploit the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203