CVE-2025-13333
IBM WebSphere Application Server vulnerability analysis and mitigation

Overview

CVE-2025-13333 is a security weakness in IBM WebSphere Application Server (WAS) versions 8.5 and 9.0 that could provide weaker than expected security during system administration of security settings. The vulnerability was published on February 17, 2026, and affects IBM WebSphere Application Server 8.5.0.0 and 9.0.0.0, as well as IBM products that ship WAS as a component, including IBM Control Desk, Maximo Asset Management, and IBM Tivoli Network Manager (ITNM) IP Edition. It carries a CVSS v3.1 base score of 4.9 (Medium), classified under CWE-358 (Improperly Implemented Security Check for Standard) (IBM Advisory, Red Hat CVE).

Technical details

The root cause is classified as CWE-358 — Improperly Implemented Security Check for Standard — meaning the application fails to correctly enforce a security standard during administrative operations related to security settings. The attack vector is network-based, requires high privileges (administrative access), low attack complexity, and no user interaction. The flaw manifests during system administration of security configurations, potentially allowing a privileged attacker to bypass or weaken security controls that should be enforced (IBM Advisory, Red Hat CVE).

Impact

Successful exploitation of this vulnerability impacts confidentiality only — integrity and availability are not affected. A network-adjacent attacker with high privileges could leverage the weakened security enforcement to access sensitive information that should otherwise be protected by the security settings being administered. The scope is limited to the affected WAS instance, but given WAS is often deployed in enterprise environments handling sensitive business data, unauthorized information disclosure could have significant downstream consequences. Downstream IBM products bundling WAS (Control Desk, Maximo Asset Management, ITNM) are also affected (IBM Advisory, IBM ITNM Bulletin).

Mitigation and workarounds

IBM has released patches addressing this vulnerability. Users of IBM WebSphere Application Server 8.5 and 9.0 should apply the fix detailed in IBM Security Bulletin node 7260217. Organizations running IBM Control Desk or Maximo Asset Management with bundled WAS should refer to IBM Security Bulletin node 7269126 for specific remediation guidance. IBM Tivoli Network Manager (ITNM) IP Edition customers should consult the dedicated ITNM bulletin. Upgrading to the patched fix pack versions as directed by IBM is the recommended remediation (IBM Advisory, IBM ASM Bulletin, IBM ITNM Bulletin).

Community reactions

Coverage of CVE-2025-13333 has been limited to standard vulnerability tracking and aggregation platforms (Tenable, Vulners, CIRCL, CVEFeed). No notable researcher commentary, social media discussion, or significant media coverage has been identified beyond routine vendor bulletins and automated CVE feeds (IBM Advisory).

Additional resources


SourceThis report was generated using AI

Related IBM WebSphere Application Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-11541CRITICAL9.8
  • IBM WebSphere Application Server logoIBM WebSphere Application Server
  • cpe:2.3:a:ibm:websphere_application_server
NoYesJun 30, 2026
CVE-2026-11714CRITICAL9.8
  • IBM WebSphere Application Server logoIBM WebSphere Application Server
  • cpe:2.3:a:ibm:websphere_application_server
NoYesJun 30, 2026
CVE-2026-11712CRITICAL9.3
  • IBM WebSphere Application Server logoIBM WebSphere Application Server
  • cpe:2.3:a:ibm:websphere_application_server
NoYesJun 30, 2026
CVE-2026-11806HIGH7.5
  • IBM WebSphere Application Server logoIBM WebSphere Application Server
  • cpe:2.3:a:ibm:websphere_application_server
NoYesJun 30, 2026
CVE-2026-11594MEDIUM6.1
  • IBM WebSphere Application Server logoIBM WebSphere Application Server
  • cpe:2.3:a:ibm:websphere_application_server
NoYesJun 30, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management