Múltiples vulnerabilidades en IBM WebSphere Application Server Vie, 21/08/2026 - 09:44

        Aviso

Recursos Afectados
          Las vulnerabilidades afectan a los siguientes productos y versiones:IBM Cloud Pak for Applications versiones 5.1, 5.2 y 5.3;IBM WebSphere Application Server Liberty versiones 17.0.0.3 hasta la 26.0.0.8 incluida;IBM Enterprise Application Runtimes versiones 1.0 y 1.1;IBM WebSphere Hybrid Edition versión 5.1;IBM WebSphere Application Server versiones 9.0.0.0 hasta la 9.0.5.28 incluida.

Descripción
          IBM ha publicado 4 vulnerabilidades: 1 de severidad crítica y 3 de severidad alta que, en caso de ser explotadas, podrían permitir a un atacante omitir la autenticación o provocar una denegación de servicio.

Identificador
          INCIBE-2026-571

Solución
          IBM recomienda encarecidamente aplicar una corrección provisional o un paquete de correcciones disponible actualmente que contenga la corrección para APAR DT496165, DT496328 y DT496327.

Detalle
          CVE-2026-14525: es vulnerable a una omisión de autenticación cuando la función rtcomm-1.0 o rtcommGateway-1.0 está habilitada.CVE-2026-57819: Apache CXF permite establecer un límite en el número de parámetros de formulario en un mensaje JAX-RS mediante la opción de configuración "maxFormParameterCount". Sin embargo, no se establece un límite predeterminado. Un atacante podría enviar solicitudes con un número muy elevado de parámetros de formulario, lo que puede provocar un ataque de denegación de servicio.CVE-2026-54225: Apache CXF permite controlar el tamaño máximo de los archivos adjuntos mediante la opción "attachment-max-size". Sin embargo, no existe un tamaño predeterminado. Un atacante podría no establecer explícitamente el límite, lo que puede provocar un ataque de denegación de servicio.CVE-2026-64958: Apache CXF permite enviar un mensaje con múltiples encabezados adjuntos. Un atacante podría aprovecharlo para provocar un ataque de denegación de servicio.

        5 - Crítica

  Listado de referencias

          Security Bulletin: IBM WebSphere Application Server Liberty, which is bundled with IBM Cloud Pak for Applications, is affected by an authentication bypass vulnerability (CVE-2026-14525)

          Security Bulletin: IBM WebSphere Application Server Liberty, which is bundled with IBM Enterprise Application Runtimes, is affected by an authentication bypass vulnerability (CVE-2026-14525)

          Security Bulletin: IBM WebSphere Application Server Liberty, which is bundled with IBM WebSphere Hybrid Edition, is affected by an authentication bypass vulnerability (CVE-2026-14525)

          Security Bulletin: IBM WebSphere Application Server and WebSphere Application Server Liberty (bundled with IBM Enterprise Application Runtimes) are affected by multiple vulnerabilities due to Apache CXF (CVE-2026-57819, CVE-2026-54225, CVE-2026-64958)

Etiquetas

                        Autenticación
                                    Aviso
                                    Denegación de servicio - DoS - DDoS
                                                    IBM
            +
                                                Vulnerabilidad
                        -

CVE

                        Identificador CVE
                        Severidad
                        Explotación
                        Fabricante

                  CVE-2026-14525
                  Crítica
                  No
                  IBM

                  CVE-2026-57819
                  Alta
                  No
                  IBM

                  CVE-2026-54225
                  Alta
                  No
                  IBM

                  CVE-2026-64958
                  Alta
                  No
                  IBM

Llegir l'article original