Use of hard-coded cryptographic key in IBM WebSphere Application Server Liberty - CVE-2025-14923

 

Use of hard-coded cryptographic key in IBM WebSphere Application Server Liberty - CVE-2025-14923

Published: April 6, 2026


Vulnerability identifier: #VU124875
CSH Severity: Low
CVSS v4: 5.7 [CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-14923
CWE-ID: CWE-321
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists due to IBM WebSphere Application Server Liberty could provide weaker than expected security when using the Security Utility when administering security settings. A local user can gain unauthorized access to sensitive information on the system.


Affected software

IBM WebSphere Application Server Liberty
IBM Tivoli Application Dependency Discovery Manager
Operations Analytics - Log Analysis
PowerVM NovaLink
Financial Transaction Manager for RedHat OpenShift
Storage Protect for Virtual Environments: Data Protection for Hyper-V
Storage Protect Client
Storage Protect for Virtual Environments: Data Protection for VMware
Maximo Application Suite - Monitor Component
IBM OpenPages with Watson
CICS Transaction Gateway for Multiplatforms
CICS Transaction Gateway Desktop Edition
Robotic Process Automation for Cloud Pak
Storage Protect Operations Center
Storage Protect for Space Management
IBM Cloud Pak System
IBM SPSS Analytic Server
IBM Watson Discovery for IBM Cloud Pak for Data
IBM TXSeries for Multiplatforms
IBM SPSS Collaboration and Deployment Services
IBM Common Licensing
IBM i
IBM InfoSphere Information Server

How to mitigate CVE-2025-14923

Install updates from vendor's website.

PowerVM NovaLink - addressed in versions 2.1.1-260428, 2.2.1.1-260428, 2.3.2-260422
IBM Cloud Pak System - update to 2.3.5.1
Financial Transaction Manager for RedHat OpenShift - update to 4.0.9.0
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.2
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.2.2.0
Storage Protect Client - update to 8.2.2.0
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.2.2.0
IBM TXSeries for Multiplatforms - update to 11.1.0.0 ifix19
Maximo Application Suite - Monitor Component - addressed in versions 8.10.30, 8.11.28, 9.0.20, 9.1.10
IBM InfoSphere Information Server - update to 11.7.1.6 Service pack 3
Robotic Process Automation for Cloud Pak - addressed in versions 23.0.20.6, 30.0.3
Storage Protect Operations Center - update to 8.2.2
Storage Protect for Space Management - update to 8.2.2.0

External References

Related Security Bulletins