CVE-2025-14915: IBM WebSphere Application Server Liberty is affected by a privilege escalation vulnerability
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is affected by privilege escalation. A privileged user could gain additional access to the application server.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server Libertyto a version that resolves this vulnerability.Fixed in 26.0.0.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch PH70327
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14915?
CVE-2025-14915 has a high severity rating due to the potential for unauthorized privilege escalation.
How do I fix CVE-2025-14915?
To mitigate CVE-2025-14915, update IBM WebSphere Application Server Liberty to the latest version beyond 26.0.0.3.
Who is affected by CVE-2025-14915?
CVE-2025-14915 affects all users of IBM WebSphere Application Server Liberty versions 17.0.0.3 to 26.0.0.3.
What type of vulnerability is CVE-2025-14915?
CVE-2025-14915 is categorized as a privilege escalation vulnerability.
Can a regular user exploit CVE-2025-14915?
No, exploitation of CVE-2025-14915 requires a privileged user account to gain additional access.