CVE-2025-14923: IBM WebSphere Application Server Liberty could provide weaker than expected security
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Server Liberty could provide weaker than expected security when using the Security Utility when administering security settings.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server Libertyto a version that resolves this vulnerability.Patch PH69658 - Upgrade
Upgrade
IBM WebSphere Application Server Libertyto a version that resolves this vulnerability.Fixed in 26.0.0.3
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14923?
CVE-2025-14923 has a medium severity rating due to its potential to weaken application security configurations.
How do I fix CVE-2025-14923?
To fix CVE-2025-14923, upgrade IBM WebSphere Application Server Liberty to a version later than 26.0.0.2.
What versions are affected by CVE-2025-14923?
CVE-2025-14923 affects IBM WebSphere Application Server Liberty versions from 17.0.0.3 to 26.0.0.2.
What impact does CVE-2025-14923 have on security?
CVE-2025-14923 could allow for weaker than expected security when administering security settings in IBM WebSphere Application Server Liberty.
Is there a workaround for CVE-2025-14923?
Currently, the recommended action for CVE-2025-14923 is to apply the latest patch or upgrade rather than relying on a workaround.