CVE-2025-14914
IBM WebSphere Application Server vulnerability analysis and mitigation

Overview

CVE-2025-14914 is a path traversal vulnerability (Zip Slip) in IBM WebSphere Application Server (WAS) Liberty that allows a privileged user to upload a specially crafted zip archive containing path traversal sequences, resulting in arbitrary file overwrite and potential arbitrary code execution. It affects WAS Liberty versions 17.0.0.3 through 26.0.0.1. The vulnerability was published on February 2, 2026, with IBM releasing a patch shortly thereafter. It carries a CVSS v3.1 base score of 7.6 (High) (IBM Advisory, ENISA EUVD).

Technical details

The root cause is improper limitation of a pathname to a restricted directory (CWE-22 / Path Traversal), a class of vulnerability commonly known as "Zip Slip." When a privileged user uploads a zip archive to the Liberty server, the application fails to sanitize path traversal sequences (e.g., ../../) embedded in archive entry names, allowing files to be written outside the intended extraction directory. Exploitation requires network access, high privileges, user interaction, and high attack complexity, but the scope is changed — meaning a successful exploit can affect resources beyond the vulnerable component itself (IBM Advisory, ENISA EUVD). No public proof-of-concept code has been identified at this time.

Impact

Successful exploitation allows an attacker to overwrite arbitrary files on the server filesystem, which can lead to arbitrary code execution on the affected system. All three security pillars are impacted at a high level: confidentiality (sensitive file access), integrity (file overwrite), and availability (service disruption or system compromise). The changed scope indicator means the impact can extend beyond the WAS Liberty process itself, potentially affecting the underlying operating system or other co-located services (IBM Advisory). Multiple IBM products that embed WAS Liberty are also affected, including IBM Business Automation Workflow, IBM Cloud Pak for Business Automation, IBM Application Performance Management, IBM Data Product Hub, and IBM Business Automation Insights (IBM APM Advisory, IBM CP4BA Advisory).

Exploitation steps

  1. Reconnaissance: Identify IBM WebSphere Application Server Liberty instances running versions 17.0.0.3 through 26.0.0.1 using network scanning tools (e.g., Nmap, Shodan) or by reviewing exposed service banners and administrative interfaces.
  2. Obtain privileged credentials: Acquire high-privilege credentials for the Liberty administrative interface through credential theft, phishing, or by chaining with another vulnerability (e.g., an authentication bypass or credential exposure flaw in the same product suite).
  3. Craft malicious zip archive: Create a zip file containing one or more entries with path traversal sequences in their filenames (e.g., ../../conf/server.xml or ../../webapps/shell.jsp) pointing to sensitive or executable locations on the server filesystem.
  4. Upload the archive: Authenticate to the Liberty administrative interface and upload the crafted zip archive via the file upload functionality exposed to privileged users.
  5. Trigger file overwrite: The server extracts the archive without sanitizing entry paths, writing attacker-controlled content to arbitrary locations outside the intended directory (e.g., overwriting a configuration file or deploying a web shell).
  6. Achieve code execution: Access the overwritten or newly created file (e.g., a deployed JSP web shell) via the web server to execute arbitrary commands on the underlying system (IBM Advisory, CSO Online).

Indicators of compromise

  • Network: Unusual HTTP POST requests to Liberty administrative or file upload endpoints from unexpected source IPs; outbound connections from the Liberty server process to unknown external hosts following a file upload event.
  • File System: Presence of unexpected files (e.g., JSP web shells, modified configuration files) outside the intended application deployment directories; modification timestamps on critical server files (e.g., server.xml, startup scripts) coinciding with upload activity.
  • Logs: Liberty access logs showing large multipart/form-data POST requests to administrative endpoints; application logs recording extraction of zip entries with ../ sequences or absolute paths; Java exceptions related to file write operations outside expected directories.
  • Process: Unusual child processes spawned by the Liberty JVM process (e.g., cmd.exe, /bin/sh, curl, wget, powershell) following a file upload event; unexpected network connections initiated by the Liberty process.

Mitigation and workarounds

IBM has released a fix in WAS Liberty version 26.0.0.2 and later; organizations should upgrade to this version or any subsequent release (IBM Advisory, Open Liberty Blog). Downstream IBM products (Business Automation Workflow, Cloud Pak for Business Automation, Application Performance Management, Data Product Hub, Business Automation Insights, and Engineering Lifecycle Management products) have received separate iFixes — consult the respective IBM security bulletins for version-specific guidance (IBM APM Advisory, IBM CP4BA Advisory). As interim mitigations, restrict file upload privileges to the minimum necessary set of users, validate and sanitize all uploaded archives before processing, and implement file integrity monitoring on critical server directories.

Community reactions

CSO Online reported that CVE-2025-14914 is one of seven IBM WebSphere Liberty vulnerabilities that security researchers noted could be chained together to achieve a full server takeover, elevating its practical risk beyond what the individual CVSS score suggests (CSO Online). German technology outlet Heise covered the disclosure in the context of multiple IBM WebSphere and Netcool OMNIbus security gaps (Heise). The vulnerability also received brief social media attention via The Hacker Wire on Mastodon and Bluesky shortly after disclosure.

Additional resources


SourceThis report was generated using AI

Related IBM WebSphere Application Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-11541CRITICAL9.8
  • IBM WebSphere Application Server logoIBM WebSphere Application Server
  • cpe:2.3:a:ibm:websphere_application_server
NoYesJun 30, 2026
CVE-2026-11714CRITICAL9.8
  • IBM WebSphere Application Server logoIBM WebSphere Application Server
  • cpe:2.3:a:ibm:websphere_application_server
NoYesJun 30, 2026
CVE-2026-11712CRITICAL9.3
  • IBM WebSphere Application Server logoIBM WebSphere Application Server
  • cpe:2.3:a:ibm:websphere_application_server
NoYesJun 30, 2026
CVE-2026-11806HIGH7.5
  • IBM WebSphere Application Server logoIBM WebSphere Application Server
  • cpe:2.3:a:ibm:websphere_application_server
NoYesJun 30, 2026
CVE-2026-11594MEDIUM6.1
  • IBM WebSphere Application Server logoIBM WebSphere Application Server
  • cpe:2.3:a:ibm:websphere_application_server
NoYesJun 30, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management