cbcvebase.
CVE-2025-13333
published 2026-02-17

CVE-2025-13333: IBM WebSphere Application Server 9.0, and 8.5 could provide weaker than expected security during system administration of security settings.

PriorityP425medium4.9CVSS 3.1
AVNACLPRHUINSUCHINAN
EPSS
0.31%
23.2th percentile
IBM WebSphere Application Server 9.0, and 8.5 could provide weaker than expected security during system administration of security settings.

Affected

4 ranges
VendorProductVersion rangeFixed in
ibmwebsphere_application_server
ibmwebsphere_application_server
ibmwebsphere_application_server8.5 – 8.5.5.29
ibmwebsphere_application_server9.0 – 9.0.5.27
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.