
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14923 is a hard-coded cryptographic key/credentials vulnerability in IBM WebSphere Application Server Liberty that causes weaker-than-expected security when using the Security Utility to administer security settings. It affects versions 17.0.0.3 through 26.0.0.2 of WebSphere Application Server Liberty. The vulnerability was published on March 3, 2026, and is classified under CWE-321 (Use of Hard-coded Cryptographic Key) and CWE-798 (Use of Hard-coded Credentials). The NVD-assigned CVSS v3.1 base score is 9.8 (Critical), though ENISA's EUVD assigns a lower score of 4.7 (Medium) under a more restrictive vector (IBM Advisory, Red Hat CVE).
The root cause is the use of hard-coded cryptographic keys (CWE-321) and hard-coded credentials (CWE-798) within the Security Utility component of IBM WebSphere Application Server Liberty. These static keys or credentials, embedded in the application, can be discovered by an attacker and used to bypass security controls — for example, to decrypt protected configuration data or impersonate privileged identities without requiring authentication. The attack vector is network-accessible with low complexity and no privileges or user interaction required (per the NVD CVSS vector), making it exploitable remotely. No public proof-of-concept code has been identified at this time (IBM Advisory, Red Hat CVE).
Successful exploitation could result in high-severity impacts to confidentiality, integrity, and availability of affected systems, as reflected in the NVD CVSS score of 9.8. Attackers with network access could leverage the hard-coded keys or credentials to gain unauthorized access to security settings, decrypt sensitive configuration data, or impersonate privileged accounts — potentially enabling full system compromise. The vulnerability affects a broad range of IBM products that bundle WebSphere Application Server Liberty, including SPSS Collaboration and Deployment Services, CICS Transaction Gateway, IBM Maximo Application Suite, IBM Business Automation Workflow, IBM Data Product Hub, IBM Voice Gateway, and others (IBM Advisory, IBM CICS Advisory).
IBM has released a fix in WebSphere Application Server Liberty version 26.0.0.3, and upgrading to this version or later is the primary recommended remediation (IBM Advisory, Open Liberty Blog). Organizations using dependent IBM products (e.g., SPSS Collaboration and Deployment Services, CICS Transaction Gateway, Maximo Application Suite, Business Automation Workflow, Data Product Hub, Voice Gateway, License Metric Tool, Operations Analytics - Log Analysis, Application Modernization Accelerator, Transformation Advisor, CICS TX Advanced, Business Automation Insights) should apply the respective product-specific iFixes or cumulative fixes published by IBM. As an interim measure, restrict network access to Security Utility administration interfaces and monitor security logs for unauthorized configuration changes.
CSO Online reported that CVE-2025-14923 is one of seven IBM WebSphere Liberty flaws that researchers noted could be chained together to achieve full system takeover, elevating its practical risk beyond what the individual score might suggest (CSO Online). IBM has issued a broad set of security bulletins covering the vulnerability's impact across its product portfolio, reflecting the wide deployment of WebSphere Application Server Liberty as an embedded component. No significant independent researcher commentary or social media discussion beyond standard CVE tracking has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."