Múltiples vulnerabilidades en IBM WebSphere Application Server Vie, 21/08/2026 - 09:44
Aviso
Recursos Afectados
Las vulnerabilidades afectan a los siguientes productos y versiones:IBM Cloud Pak for Applications versiones 5.1, 5.2 y 5.3;IBM WebSphere Application Server Liberty versiones 17.0.0.3 hasta la 26.0.0.8 incluida;IBM Enterprise Application Runtimes versiones 1.0 y 1.1;IBM WebSphere Hybrid Edition versión 5.1;IBM WebSphere Application Server versiones 9.0.0.0 hasta la 9.0.5.28 incluida.
Descripción
IBM ha publicado 4 vulnerabilidades: 1 de severidad crítica y 3 de severidad alta que, en caso de ser explotadas, podrían permitir a un atacante omitir la autenticación o provocar una denegación de servicio.
Identificador
INCIBE-2026-571
Solución
IBM recomienda encarecidamente aplicar una corrección provisional o un paquete de correcciones disponible actualmente que contenga la corrección para APAR DT496165, DT496328 y DT496327.
Detalle
CVE-2026-14525: es vulnerable a una omisión de autenticación cuando la función rtcomm-1.0 o rtcommGateway-1.0 está habilitada.CVE-2026-57819: Apache CXF permite establecer un límite en el número de parámetros de formulario en un mensaje JAX-RS mediante la opción de configuración "maxFormParameterCount". Sin embargo, no se establece un límite predeterminado. Un atacante podría enviar solicitudes con un número muy elevado de parámetros de formulario, lo que puede provocar un ataque de denegación de servicio.CVE-2026-54225: Apache CXF permite controlar el tamaño máximo de los archivos adjuntos mediante la opción "attachment-max-size". Sin embargo, no existe un tamaño predeterminado. Un atacante podría no establecer explícitamente el límite, lo que puede provocar un ataque de denegación de servicio.CVE-2026-64958: Apache CXF permite enviar un mensaje con múltiples encabezados adjuntos. Un atacante podría aprovecharlo para provocar un ataque de denegación de servicio.
5 - Crítica
Listado de referencias
Security Bulletin: IBM WebSphere Application Server Liberty, which is bundled with IBM Cloud Pak for Applications, is affected by an authentication bypass vulnerability (CVE-2026-14525)
Security Bulletin: IBM WebSphere Application Server Liberty, which is bundled with IBM Enterprise Application Runtimes, is affected by an authentication bypass vulnerability (CVE-2026-14525)
Security Bulletin: IBM WebSphere Application Server Liberty, which is bundled with IBM WebSphere Hybrid Edition, is affected by an authentication bypass vulnerability (CVE-2026-14525)
Security Bulletin: IBM WebSphere Application Server and WebSphere Application Server Liberty (bundled with IBM Enterprise Application Runtimes) are affected by multiple vulnerabilities due to Apache CXF (CVE-2026-57819, CVE-2026-54225, CVE-2026-64958)
Etiquetas
Autenticación
Aviso
Denegación de servicio - DoS - DDoS
IBM
+
Vulnerabilidad
-
CVE
Identificador CVE
Severidad
Explotación
Fabricante
CVE-2026-14525
Crítica
No
IBM
CVE-2026-57819
Alta
No
IBM
CVE-2026-54225
Alta
No
IBM
CVE-2026-64958
Alta
No
IBM