SB2026040626 - Use of hard-coded credentials in IBM WebSphere Application Server - Liberty
Published: April 6, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Use of hard-coded cryptographic key (CVE-ID: CVE-2025-14923)
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to IBM WebSphere Application Server Liberty could provide weaker than expected security when using the Security Utility when administering security settings. A local user can gain unauthorized access to sensitive information on the system.
Remediation
Install update from vendor's website.