IBM Product Security Update Advisory

IBM Product Security Update Advisory

Overview


IBM has released security updates to address vulnerabilities in IBM WebSphere Application Server and WebSphere Application Server – Liberty. Users of these products should apply the latest version or the specified interim fix.

Affected Products and Vulnerabilities


  • CVE-2026-14529: A server-side request forgery (SSRF) vulnerability affecting IBM WebSphere Application Server and WebSphere Application Server – Liberty.
  • CVE-2026-15057: A denial-of-service (DoS) vulnerability in IBM WebSphere Application Server – Liberty caused by uncontrolled heap allocation.

Affected Versions and Fixed Versions


  • CVE-2026-14529
    • IBM WebSphere Application Server 8.5.0.0 Through 8.5.5.30
    • IBM WebSphere Application Server 9.0.0.0 Through 9.0.5.28
    • IBM WebSphere Application Server – Liberty 17.0.0.3 Through 26.0.0.8
    • Fixed versions: IBM WebSphere Application Server 8.5.5.31 Or later, 9.0.5.29 Or later, IBM WebSphere Application Server – Liberty 26.0.0.9 Or later, or apply APAR DT495928 Interim Fix or APAR PH72053 Interim Fix
  • CVE-2026-15057
    • IBM WebSphere Application Server – Liberty 17.0.0.3 Or later through 26.0.0.7
    • Resolved versions: IBM WebSphere Application Server – Liberty 26.0.0.8 Or later, or apply APAR PH72167 Interim Fix

Action Required


IBM recommends updating to the latest version with the Vulnerability Patch, as outlined in the reference site.