
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14914 is a path traversal vulnerability (Zip Slip) in IBM WebSphere Application Server (WAS) Liberty that allows a privileged user to upload a specially crafted zip archive containing path traversal sequences, resulting in arbitrary file overwrite and potential arbitrary code execution. It affects WAS Liberty versions 17.0.0.3 through 26.0.0.1. The vulnerability was published on February 2, 2026, with IBM releasing a patch shortly thereafter. It carries a CVSS v3.1 base score of 7.6 (High) (IBM Advisory, ENISA EUVD).
The root cause is improper limitation of a pathname to a restricted directory (CWE-22 / Path Traversal), a class of vulnerability commonly known as "Zip Slip." When a privileged user uploads a zip archive to the Liberty server, the application fails to sanitize path traversal sequences (e.g., ../../) embedded in archive entry names, allowing files to be written outside the intended extraction directory. Exploitation requires network access, high privileges, user interaction, and high attack complexity, but the scope is changed — meaning a successful exploit can affect resources beyond the vulnerable component itself (IBM Advisory, ENISA EUVD). No public proof-of-concept code has been identified at this time.
Successful exploitation allows an attacker to overwrite arbitrary files on the server filesystem, which can lead to arbitrary code execution on the affected system. All three security pillars are impacted at a high level: confidentiality (sensitive file access), integrity (file overwrite), and availability (service disruption or system compromise). The changed scope indicator means the impact can extend beyond the WAS Liberty process itself, potentially affecting the underlying operating system or other co-located services (IBM Advisory). Multiple IBM products that embed WAS Liberty are also affected, including IBM Business Automation Workflow, IBM Cloud Pak for Business Automation, IBM Application Performance Management, IBM Data Product Hub, and IBM Business Automation Insights (IBM APM Advisory, IBM CP4BA Advisory).
../../conf/server.xml or ../../webapps/shell.jsp) pointing to sensitive or executable locations on the server filesystem.server.xml, startup scripts) coinciding with upload activity.../ sequences or absolute paths; Java exceptions related to file write operations outside expected directories.cmd.exe, /bin/sh, curl, wget, powershell) following a file upload event; unexpected network connections initiated by the Liberty process.IBM has released a fix in WAS Liberty version 26.0.0.2 and later; organizations should upgrade to this version or any subsequent release (IBM Advisory, Open Liberty Blog). Downstream IBM products (Business Automation Workflow, Cloud Pak for Business Automation, Application Performance Management, Data Product Hub, Business Automation Insights, and Engineering Lifecycle Management products) have received separate iFixes — consult the respective IBM security bulletins for version-specific guidance (IBM APM Advisory, IBM CP4BA Advisory). As interim mitigations, restrict file upload privileges to the minimum necessary set of users, validate and sanitize all uploaded archives before processing, and implement file integrity monitoring on critical server directories.
CSO Online reported that CVE-2025-14914 is one of seven IBM WebSphere Liberty vulnerabilities that security researchers noted could be chained together to achieve a full server takeover, elevating its practical risk beyond what the individual CVSS score suggests (CSO Online). German technology outlet Heise covered the disclosure in the context of multiple IBM WebSphere and Netcool OMNIbus security gaps (Heise). The vulnerability also received brief social media attention via The Hacker Wire on Mastodon and Bluesky shortly after disclosure.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."