Subscribe to this APAR
Action required for important upcoming changes to the Liberty container images.
As part of our ongoing commitment to improving security, reducing vulnerability exposure, and aligning with container best practices, we are announcing two important updates to the Universal Base Image (UBI) operating system variants used in the official container images for IBM WebSphere Liberty and Open Liberty....
1) Liberty images updating from UBI 9 Minimal to UBI 10 Minimal inDESCRIPTION: libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.
CWE: CWE-476:NULL Pointer Dereference[2]
...
DESCRIPTION: IBM WebSphere Application Server Liberty could provide weaker than expected security when administering security settings.
CWE: CWE-1393:Use of Default Password[2]
...
Weitere Beiträge ...
- PH70327:IBM WebSphere Application Server Liberty is affected by a privilege escalation vulnerability (CVE-2025-14915 CVSS 6.5)
- IBM WebSphere Application Server Liberty is affected by a prototype pollution vulnerability due to immutable (CVE-2026-29063)
- IBM WebSphere Application Server Liberty is affected by server-side request forgery (CVE-2026-1561)
- IBM WebSphere Application Server Liberty is affected by a privilege escalation vulnerability (CVE-2025-14915)
Seite 1 von 51