CVE-2025-2134: IBM Jazz Reporting Service Denial of Service

Published Feb 4, 2026
·
Updated

IBM Jazz Reporting Service could allow an authenticated user on the network to affect the system's performance using complicated queries due to insufficient resource pooling.

Affected Software

29 affected components
IBM Jazz Reporting Service
IBM Jazz Reporting Service=7.0.3
IBM Jazz Reporting Service=7.0.3-ifix001
IBM Jazz Reporting Service=7.0.3-ifix002
IBM Jazz Reporting Service=7.0.3-ifix003
IBM Jazz Reporting Service=7.0.3-ifix004
IBM Jazz Reporting Service=7.0.3-ifix005
IBM Jazz Reporting Service=7.0.3-ifix006
IBM Jazz Reporting Service=7.0.3-ifix007
IBM Jazz Reporting Service=7.0.3-ifix008
IBM Jazz Reporting Service=7.0.3-ifix009
IBM Jazz Reporting Service=7.0.3-ifix010
IBM Jazz Reporting Service=7.0.3-ifix011
IBM Jazz Reporting Service=7.0.3-ifix012
IBM Jazz Reporting Service=7.0.3-ifix013
IBM Jazz Reporting Service=7.0.3-ifix014
IBM Jazz Reporting Service=7.0.3-ifix015
IBM Jazz Reporting Service=7.0.3-ifix016
IBM Jazz Reporting Service=7.0.3-ifix017
IBM Jazz Reporting Service=7.0.3-ifix018
IBM Jazz Reporting Service=7.0.3-ifix019
IBM Jazz Reporting Service=7.0.3-ifix020
IBM Jazz Reporting Service=7.1
IBM Jazz Reporting Service=7.1-ifix001
IBM Jazz Reporting Service=7.1-ifix002
IBM Jazz Reporting Service=7.1-ifix003
IBM Jazz Reporting Service=7.1-ifix004-sr1-base
IBM Jazz Reporting Service=7.1-ifix005
IBM Jazz Reporting Service=7.1-ifix006

Remediation

Information

IBM strongly recommends addressing the vulnerability now by applying the iFix listed below: ProductVersioniFixRemediation / First FixIBM Jazz Reporting Service7.17.1iFix007 Fix Central - 7.1 https://www.ibm.com/support/fixcentral/swg/downloadFixes IBM Jazz Reporting Service7.0.37.0.3iFix021 Fix Central - 7.0.3 https://www.ibm.com/support/fixcentral/swg/doSelectFixes

Event History

Feb 4, 2026
CVE Published
via MITRE·09:07 PM
Data Sourced
via MITRE·09:07 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-2134?

CVE-2025-2134 is considered a moderate-severity vulnerability affecting IBM Jazz Reporting Service.

2

How do I fix CVE-2025-2134?

To mitigate CVE-2025-2134, you should apply the latest patches and updates provided by IBM for the Jazz Reporting Service.

3

Who is affected by CVE-2025-2134?

CVE-2025-2134 affects authenticated users of IBM Jazz Reporting Service who can execute complex queries.

4

What are the potential impacts of CVE-2025-2134?

The potential impact of CVE-2025-2134 includes performance degradation of the system due to resource exhaustion from complex queries.

5

Is there a workaround for CVE-2025-2134?

A temporary workaround for CVE-2025-2134 may involve limiting user permissions for executing complex queries on IBM Jazz Reporting Service.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203