CVE-2025-14923

MEDIUM

IBM WebSphere Liberty 17.0.0.3-26.0.0.2 - Auth Bypass

Title source: llm
STIX 2.1

Description

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Server Liberty could provide weaker than expected security when using the Security Utility when administering security settings.

Scores

CVSS v3 4.7
EPSS 0.0003
EPSS Percentile 8.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-798 CWE-321
Status published
Products (1)
ibm/websphere_application_server 17.0.0.3 - 26.0.0.3
Published Mar 03, 2026
Tracked Since Mar 04, 2026