
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13333 is a security weakness in IBM WebSphere Application Server (WAS) versions 8.5 and 9.0 that could provide weaker than expected security during system administration of security settings. The vulnerability was published on February 17, 2026, and affects IBM WebSphere Application Server 8.5.0.0 and 9.0.0.0, as well as IBM products that ship WAS as a component, including IBM Control Desk, Maximo Asset Management, and IBM Tivoli Network Manager (ITNM) IP Edition. It carries a CVSS v3.1 base score of 4.9 (Medium), classified under CWE-358 (Improperly Implemented Security Check for Standard) (IBM Advisory, Red Hat CVE).
The root cause is classified as CWE-358 — Improperly Implemented Security Check for Standard — meaning the application fails to correctly enforce a security standard during administrative operations related to security settings. The attack vector is network-based, requires high privileges (administrative access), low attack complexity, and no user interaction. The flaw manifests during system administration of security configurations, potentially allowing a privileged attacker to bypass or weaken security controls that should be enforced (IBM Advisory, Red Hat CVE).
Successful exploitation of this vulnerability impacts confidentiality only — integrity and availability are not affected. A network-adjacent attacker with high privileges could leverage the weakened security enforcement to access sensitive information that should otherwise be protected by the security settings being administered. The scope is limited to the affected WAS instance, but given WAS is often deployed in enterprise environments handling sensitive business data, unauthorized information disclosure could have significant downstream consequences. Downstream IBM products bundling WAS (Control Desk, Maximo Asset Management, ITNM) are also affected (IBM Advisory, IBM ITNM Bulletin).
IBM has released patches addressing this vulnerability. Users of IBM WebSphere Application Server 8.5 and 9.0 should apply the fix detailed in IBM Security Bulletin node 7260217. Organizations running IBM Control Desk or Maximo Asset Management with bundled WAS should refer to IBM Security Bulletin node 7269126 for specific remediation guidance. IBM Tivoli Network Manager (ITNM) IP Edition customers should consult the dedicated ITNM bulletin. Upgrading to the patched fix pack versions as directed by IBM is the recommended remediation (IBM Advisory, IBM ASM Bulletin, IBM ITNM Bulletin).
Coverage of CVE-2025-13333 has been limited to standard vulnerability tracking and aggregation platforms (Tenable, Vulners, CIRCL, CVEFeed). No notable researcher commentary, social media discussion, or significant media coverage has been identified beyond routine vendor bulletins and automated CVE feeds (IBM Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."