Security update: IBM WebSphere Application Server vulnerable to malicious code
IBM WebSphere Application Server protects against possible attacks via temporary fixes.
(Image: Artur Szczybylo/Shutterstock.com)
Certain versions of IBM WebSphere Application Server are vulnerable to malicious code attacks. The developers advise admins to protect their servers with available temporary fixes. So far, there are no reports that attackers are already exploiting the vulnerability.
Secure systems
A warning message states that remote attackers can exploit the “critical” vulnerability (CVE-2025-36038). Due to insufficient checks, they can execute malicious code in the context of a specially crafted sequence of serialized objects and compromise systems.
According to the developers, versions 8.5 and 9.0 are vulnerable to this. Only preliminary fixes are currently available to protect PCs from such attacks. Security updates are to follow in the third quarter.
(des)