Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-36128

Опубликовано: 16 окт. 2025
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

IBM MQ 9.1, 9.2, 9.3, 9.4 LTS and 9.3, 9.4 CD is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations. By conducting slowloris-type attacks, a remote attacker could exploit this vulnerability to cause a denial of service.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:a:ibm:mq:9.1.0.0:*:*:*:lts:*:*:*
cpe:2.3:a:ibm:mq:9.2.0.0:*:*:*:lts:*:*:*
cpe:2.3:a:ibm:mq:9.3.0:*:*:*:continuous_delivery:*:*:*
cpe:2.3:a:ibm:mq:9.3.0.0:*:*:*:lts:*:*:*
cpe:2.3:a:ibm:mq:9.4.0:*:*:*:continuous_delivery:*:*:*
cpe:2.3:a:ibm:mq:9.4.0.0:*:*:*:lts:*:*:*

Одно из

cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:oracle:solaris:-:*:*:*:*:*:*:*

EPSS

Процентиль: 35%
0.00143
Низкий

7.5 High

CVSS3

Дефекты

CWE-772

Связанные уязвимости

CVSS3: 7.5
github
4 месяца назад

IBM MQ 9.1, 9.2, 9.3, 9.4 LTS and 9.3, 9.4 CD is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations. By conducting slowloris-type attacks, a remote attacker could exploit this vulnerability to cause a denial of service.

EPSS

Процентиль: 35%
0.00143
Низкий

7.5 High

CVSS3

Дефекты

CWE-772