CVE-2025-14923

MEDIUM

IBM WebSphere Liberty 17.0.0.3-26.0.0.2 - Auth Bypass

Title source: llm

Description

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Server Liberty could provide weaker than expected security when using the Security Utility when administering security settings.

Scores

CVSS v3 4.7
EPSS 0.0003
EPSS Percentile 6.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-321 CWE-798
Status published

Affected Products (1)

ibm/websphere_application_server < 26.0.0.3

Timeline

Published Mar 03, 2026
Tracked Since Mar 04, 2026