CVE-2025-14915
published 2026-03-25CVE-2025-14915: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is affected by privilege escalation. A privileged…
PriorityP342high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
0.50%
39.8th percentile
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is affected by privilege escalation. A privileged user could gain additional access to the application server.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | websphere_application_server | >= 17.0.0.3 < 26.0.0.4 | 26.0.0.4 |
| ibm | websphere_application_server_liberty | 17.0.0.3 – 26.0.0.3 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2025-14915 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.4
CVE-2025-14915 [MEDIUM] CVE-2025-14915 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-14915 :
IBM WebSphere Application Server vulnerability analysis and mitigation
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is affected by privilege escalation. A privileged user could gain additional access to the application server.
Source : NVD
## 7.2
Score
Published March 25, 2026
Severity HIGH
CNA Score 6.5
Affected Technologies
IBM WebSphere Application Server
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ibm:websphere_application_server
Sources
Linux Severity HIGH Has Fix Added at: Mar 31, 2026
Windows Severity HI
Wiz
CVE-2025-14914 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.4
CVE-2025-14914 [MEDIUM] CVE-2025-14914 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-14914 :
IBM WebSphere Application Server vulnerability analysis and mitigation
IBM WebSphere Application Server Liberty 17.0.0.3 through 26.0.0.1 could allow a privileged user to upload a zip archive containing path traversal sequences resulting in an overwrite of files leading to arbitrary code execution.
Source : NVD
## 7.6
Score
Published February 2, 2026
Severity HIGH
CNA Score 7.6
Affected Technologies
IBM WebSphere Application Server
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ibm:websphere_application_server
Sources
Linux Severity HIGH No Fix Added at: Feb 03, 2026
Windows Sev
Wiz
CVE-2025-13333 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.4
CVE-2025-13333 [MEDIUM] CVE-2025-13333 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-13333 :
IBM WebSphere Application Server vulnerability analysis and mitigation
IBM WebSphere Application Server 9.0, and 8.5 could provide weaker than expected security during system administration of security settings.
Source : NVD
## 4.9
Score
Published February 17, 2026
Severity MEDIUM
CNA Score 4.4
Affected Technologies
IBM WebSphere Application Server
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ibm:websphere_application_server
Sources
Linux Severity MEDIUM No Fix Added at: Feb 18, 2026
Windows Severity MEDIUM No Fix Added at: Feb 18, 2026
Linux Severity MEDIUM Has Fix Added at:
Wiz
CVE-2025-14917 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.4
CVE-2025-14917 [MEDIUM] CVE-2025-14917 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-14917 :
IBM WebSphere Application Server vulnerability analysis and mitigation
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty could provide weaker than expected security when administering security settings.
Source : NVD
## 9.8
Score
Published March 25, 2026
Severity CRITICAL
CNA Score 6.7
Affected Technologies
IBM WebSphere Application Server
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.9
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ibm:websphere_application_server
Sources
Linux Severity CRITICAL Has Fix Added at: Mar 31, 2026
Windows Severity CRITICAL Has Fix Added
Wiz
CVE-2026-1561 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.4
CVE-2026-1561 [MEDIUM] CVE-2026-1561 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1561 :
IBM WebSphere Application Server vulnerability analysis and mitigation
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is vulnerable to server-side request forgery (SSRF). This may allow remote attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
Source : NVD
## 5.4
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
IBM WebSphere Application Server
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 9.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ibm:websphere_applic
Wiz
CVE-2025-14923 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.4
CVE-2025-14923 [MEDIUM] CVE-2025-14923 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-14923 :
IBM WebSphere Application Server vulnerability analysis and mitigation
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Server Liberty could provide weaker than expected security when using the Security Utility when administering security settings.
Source : NVD
## 9.8
Score
Published March 3, 2026
Severity CRITICAL
CNA Score 4.7
Affected Technologies
IBM WebSphere Application Server
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ibm:websphere_application_server
Sources
Linux Severity CRITICAL Has Fix Added at: Mar 04, 2026
Windows Se
2026-03-25
Published