#VU124831 Weak password requirements in IBM WebSphere Application Server Liberty - CVE-2025-14917
Published: April 2, 2026
IBM WebSphere Application Server Liberty
IBM Corporation
Description
The vulnerability allows an attacker to perform a brute-force attack.
The vulnerability exists due to weak password requirements when the appSecurity-1.0, appSecurity-2.0, appSecurity-3.0, appSecurity-4.0 or appSecurity-5.0 feature is enabled. As a result users can set weak passwords to access their accounts. A remote attacker can perform brute-force attack and gain unauthorized access to the application.