Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

IBM WebSphere Application Server - Liberty Security Settings May Be Weakened

CVE-2025-14923
Summary

IBM WebSphere Application Server Liberty's Security Utility may not properly secure security settings when used for administration. This could allow unauthorized changes to security settings, potentially compromising system security. Update to a fixed version to ensure proper security settings are enforced.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
ibm websphere_application_server > 17.0.0.3 , <= 26.0.0.3 –
Original title
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Server Liberty could provide weaker than expected security when using the Security Utility when admini...
Original description
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Server Liberty could provide weaker than expected security when using the Security Utility when administering security settings.
nvd CVSS3.1 9.8
Vulnerability type
CWE-321 Use of Hard-coded Cryptographic Key
CWE-798 Use of Hard-coded Credentials
Published: 3 Mar 2026 · Updated: 13 Mar 2026 · First seen: 6 Mar 2026