CVE-2025-14923
published 2026-03-03CVE-2025-14923: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Server Liberty could provide weaker than expected security when…
PriorityP347critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.17%
7.0th percentile
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Server Liberty could provide weaker than expected security when using the Security Utility when administering security settings.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | websphere_application_server | >= 17.0.0.3 < 26.0.0.3 | 26.0.0.3 |
| ibm | websphere_application_server_liberty | 17.0.0.3 – 26.0.0.2 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
IBM WebSphere Application Server up to 26.0.0.2 Security Utility hard-coded key (WID-SEC-2026-1687)
vuldb·2026-05-28·CVSS 9.8
CVE-2025-14923 [CRITICAL] IBM WebSphere Application Server up to 26.0.0.2 Security Utility hard-coded key (WID-SEC-2026-1687)
A vulnerability labeled as problematic has been found in IBM WebSphere Application Server up to 26.0.0.2. This impacts an unknown function of the component Security Utility. Executing a manipulation can lead to use of hard-coded cryptographic key
.
This vulnerability is registered as CVE-2025-14923. The attack needs to be launched locally. No exploit is available.
The affected component should be upgraded.
GHSA
GHSA-c6r7-vwx9-8xmh: IBM WebSphere Application Server - Liberty 17
ghsa_unreviewed·2026-03-03
CVE-2025-14923 [MEDIUM] CWE-321 GHSA-c6r7-vwx9-8xmh: IBM WebSphere Application Server - Liberty 17
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Server Liberty could provide weaker than expected security when using the Security Utility when administering security settings.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2025-14915 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.4
CVE-2025-14915 [MEDIUM] CVE-2025-14915 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-14915 :
IBM WebSphere Application Server vulnerability analysis and mitigation
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is affected by privilege escalation. A privileged user could gain additional access to the application server.
Source : NVD
## 7.2
Score
Published March 25, 2026
Severity HIGH
CNA Score 6.5
Affected Technologies
IBM WebSphere Application Server
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ibm:websphere_application_server
Sources
Linux Severity HIGH Has Fix Added at: Mar 31, 2026
Windows Severity HI
Wiz
CVE-2025-14914 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.4
CVE-2025-14914 [MEDIUM] CVE-2025-14914 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-14914 :
IBM WebSphere Application Server vulnerability analysis and mitigation
IBM WebSphere Application Server Liberty 17.0.0.3 through 26.0.0.1 could allow a privileged user to upload a zip archive containing path traversal sequences resulting in an overwrite of files leading to arbitrary code execution.
Source : NVD
## 7.6
Score
Published February 2, 2026
Severity HIGH
CNA Score 7.6
Affected Technologies
IBM WebSphere Application Server
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ibm:websphere_application_server
Sources
Linux Severity HIGH No Fix Added at: Feb 03, 2026
Windows Sev
Wiz
CVE-2025-13333 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.4
CVE-2025-13333 [MEDIUM] CVE-2025-13333 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-13333 :
IBM WebSphere Application Server vulnerability analysis and mitigation
IBM WebSphere Application Server 9.0, and 8.5 could provide weaker than expected security during system administration of security settings.
Source : NVD
## 4.9
Score
Published February 17, 2026
Severity MEDIUM
CNA Score 4.4
Affected Technologies
IBM WebSphere Application Server
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ibm:websphere_application_server
Sources
Linux Severity MEDIUM No Fix Added at: Feb 18, 2026
Windows Severity MEDIUM No Fix Added at: Feb 18, 2026
Linux Severity MEDIUM Has Fix Added at:
Wiz
CVE-2025-14917 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.4
CVE-2025-14917 [MEDIUM] CVE-2025-14917 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-14917 :
IBM WebSphere Application Server vulnerability analysis and mitigation
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty could provide weaker than expected security when administering security settings.
Source : NVD
## 9.8
Score
Published March 25, 2026
Severity CRITICAL
CNA Score 6.7
Affected Technologies
IBM WebSphere Application Server
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.9
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ibm:websphere_application_server
Sources
Linux Severity CRITICAL Has Fix Added at: Mar 31, 2026
Windows Severity CRITICAL Has Fix Added
Wiz
CVE-2026-1561 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.4
CVE-2026-1561 [MEDIUM] CVE-2026-1561 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1561 :
IBM WebSphere Application Server vulnerability analysis and mitigation
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is vulnerable to server-side request forgery (SSRF). This may allow remote attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
Source : NVD
## 5.4
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
IBM WebSphere Application Server
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 9.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ibm:websphere_applic
Wiz
CVE-2025-14923 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.4
CVE-2025-14923 [MEDIUM] CVE-2025-14923 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-14923 :
IBM WebSphere Application Server vulnerability analysis and mitigation
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Server Liberty could provide weaker than expected security when using the Security Utility when administering security settings.
Source : NVD
## 9.8
Score
Published March 3, 2026
Severity CRITICAL
CNA Score 4.7
Affected Technologies
IBM WebSphere Application Server
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ibm:websphere_application_server
Sources
Linux Severity CRITICAL Has Fix Added at: Mar 04, 2026
Windows Se
2026-03-03
Published