CVE-2025-14914: IBM WebSphere Application Server Liberty Path Traversal
IBM WebSphere Application Server Liberty 17.0.0.3 through 26.0.0.1 could allow a privileged user to upload a zip archive containing path traversal sequences resulting in an overwrite of files leading to arbitrary code execution.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14914?
CVE-2025-14914 has been rated as high severity due to its potential for arbitrary code execution.
How do I fix CVE-2025-14914?
To mitigate CVE-2025-14914, upgrade IBM WebSphere Application Server Liberty to a version above 26.0.0.1.
What type of vulnerability is CVE-2025-14914?
CVE-2025-14914 is a path traversal vulnerability that allows unauthorized file access and can lead to arbitrary code execution.
Who is affected by CVE-2025-14914?
CVE-2025-14914 affects users of IBM WebSphere Application Server Liberty versions from 17.0.0.3 to 26.0.0.1.
Can CVE-2025-14914 be exploited remotely?
Yes, CVE-2025-14914 can be exploited remotely by a privileged user to upload malicious zip archives.