Path traversal in IBM WebSphere Application Server Liberty - CVE-2025-14914

 

Path traversal in IBM WebSphere Application Server Liberty - CVE-2025-14914

Published: February 12, 2026


Vulnerability identifier: #VU122748
CSH Severity: Low
CVSS v4: 5 [CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H]
CVE-ID: CVE-2025-14914
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote privileged user to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences. A remote privileged user can send a specially crafted HTTP request and read arbitrary files on the system.


Affected software

IBM WebSphere Application Server Liberty
Enterprise Application Runtimes
Operations Analytics - Log Analysis
PowerVM NovaLink
Financial Transaction Manager for RedHat OpenShift
WebSphere Hybrid Edition
Cloud Pak for Applications
Storage Protect for Space Management
Storage Protect Client
Storage Protect for Virtual Environments: Data Protection for Hyper-V
Storage Protect for Virtual Environments: Data Protection for VMware
Storage Protect Operations Center
Maximo Application Suite - Monitor Component
IBM OpenPages with Watson
Maximo Application Suite - Predict Component
Robotic Process Automation for Cloud Pak
IBM SPSS Analytic Server
IBM Cloud Application Performance Management (APM)
IBM TXSeries for Multiplatforms
IBM SPSS Collaboration and Deployment Services
IBM Maximo Application Suite
IBM Transformation Extender Advanced
IBM MQ
IBM Tivoli Application Dependency Discovery Manager
IBM CICS TX Advanced
IBM CICS TX Standard

How to mitigate CVE-2025-14914

Install updates from vendor's website.

Operations Analytics - Log Analysis - update to 1.3.8.2
PowerVM NovaLink - addressed in versions 2.1.1-260428, 2.2.1.1-260428, 2.3.2-260422
Financial Transaction Manager for RedHat OpenShift - update to 4.0.9.0
Storage Protect for Space Management - update to 8.2.2.0
Storage Protect Client - update to 8.2.2.0
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.2.2.0
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.2.2.0
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.19
Storage Protect Operations Center - update to 8.2.1
Maximo Application Suite - Monitor Component - addressed in versions 8.10.30, 8.11.28, 9.0.20, 9.1.10
IBM Maximo Application Suite - addressed in versions 8.10.37, 8.11.34, 9.0.24, 9.1.16
Maximo Application Suite - Predict Component - addressed in versions 8.8.15, 8.9.17, 9.0.14, 9.1.7
IBM CICS TX Advanced - update to 10.1.0.0 ifix47
IBM MQ - addressed in versions 9.1.0.34, 9.2.0.41, 9.3.0.37, 9.4.0.20, 9.4.5.1
IBM CICS TX Standard - update to 11.1.0.0 ifix40
Robotic Process Automation for Cloud Pak - addressed in versions 23.0.20.6, 30.0.2

External References

Related Security Bulletins