CVE-2025-36128: IBM MQ denial of service
IBM MQ 9.1, 9.2, 9.3, 9.4 LTS and 9.3, 9.4 CD is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations. By conducting slowloris-type attacks, a remote attacker could exploit this vulnerability to cause a denial of service.
Other sources
IBM MQ is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations. By conducting slowloris-type attacks, a remote attacker could exploit this vulnerability to cause a denial of service.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36128?
CVE-2025-36128 has a high severity rating due to its potential for causing denial of service attacks.
How does CVE-2025-36128 affect IBM MQ?
CVE-2025-36128 affects IBM MQ versions 9.1 through 9.4 and can be exploited by an attacker to conduct slowloris-type attacks.
How do I fix CVE-2025-36128?
To fix CVE-2025-36128, upgrade to the latest patched version of IBM MQ that addresses this vulnerability.
What are the symptoms of exploitation for CVE-2025-36128?
Symptoms of exploitation of CVE-2025-36128 may include degraded service performance or complete service unavailability.
Who is affected by CVE-2025-36128?
Organizations using IBM MQ versions 9.1, 9.2, 9.3, and up to 9.4 LTS and CD are affected by CVE-2025-36128.