CVE-2025-36128: IBM MQ denial of service

Published Oct 16, 2025
·
Updated

IBM MQ 9.1, 9.2, 9.3, 9.4 LTS and 9.3, 9.4 CD is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations. By conducting slowloris-type attacks, a remote attacker could exploit this vulnerability to cause a denial of service.

Other sources

IBM MQ is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations. By conducting slowloris-type attacks, a remote attacker could exploit this vulnerability to cause a denial of service.

IBM

Affected Software

18 affected components
IBM MQ>=9.1<=9.4
IBM MQ<=9.1 LTS
IBM MQ<=9.2 LTS
IBM MQ<=9.3 LTS
IBM MQ<=9.3 CD
IBM MQ<=9.4 LTS
IBM MQ<=9.4 CD
All of the following
Any of the following
IBM MQ=9.1.0.0
IBM MQ=9.2.0.0
IBM MQ=9.3.0
IBM MQ=9.3.0.0
IBM MQ=9.4.0
IBM MQ=9.4.0.0
Any of the following
IBM AIX
IBM i
Linux Linux kernel
Microsoft Windows
Oracle Solaris

Remediation

Information

To secure IBM WebSphere Liberty profile shipped with IBM MQ from Slowloris DDoS attacks, use one of the following methods: 1. Load Balancer Configuration If the setup involves a load balancer in front of the IBM WebSphere Liberty profile of IBM MQ, configure the load balancer to handle Slowloris-style attacks. A load balancer acts as an intermediary between clients and Liberty, distributing incoming requests across multiple backend servers. By using hardware load balancers with properly configured HTTP profiles, only complete and valid HTTP requests are forwarded to the web server, effectively filtering out the partial requests caused by Slowloris. This approach helps to prevent the attack from overwhelming the server, allowing it to continue serving legitimate traffic. Refer to IBM WebSphere Liberty documentation for configuration details. 2. Reverse Proxy Consider using a reverse proxy to handle client requests. The reverse proxy can implement various security measures, including request buffering and handling connection timeouts, to mitigate Slowloris attacks. 3. Web Application Firewall (WAF) Deploy a Web Application Firewall that can detect and block Slowloris-style attacks. A WAF can analyze incoming traffic, identify suspicious patterns indicative of Slowloris attacks, and block such requests before they reach the application server. 4. Limit Concurrent Connections Implement a limit on the number of concurrent connections allowed from a single IP address or source. This helps to prevent an attack from establishing numerous connections and consuming all available server resources. 5. Traffic Rate Limiting Implement rate-limiting mechanisms on the server to restrict the number of requests from a single IP address or source within a specific time frame. This method helps to prevent an attack from sending a pool of requests in a short period.

Event History

Oct 16, 2025
CVE Published
via MITRE·04:49 PM
Data Sourced
via MITRE·04:49 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via IBM·05:01 PM
DescriptionAffected Software
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-36128?

CVE-2025-36128 has a high severity rating due to its potential for causing denial of service attacks.

2

How does CVE-2025-36128 affect IBM MQ?

CVE-2025-36128 affects IBM MQ versions 9.1 through 9.4 and can be exploited by an attacker to conduct slowloris-type attacks.

3

How do I fix CVE-2025-36128?

To fix CVE-2025-36128, upgrade to the latest patched version of IBM MQ that addresses this vulnerability.

4

What are the symptoms of exploitation for CVE-2025-36128?

Symptoms of exploitation of CVE-2025-36128 may include degraded service performance or complete service unavailability.

5

Who is affected by CVE-2025-36128?

Organizations using IBM MQ versions 9.1, 9.2, 9.3, and up to 9.4 LTS and CD are affected by CVE-2025-36128.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203