CVE-2026-14974: IBM WebSphere Application Server is affected by cross-site scripting and deserialization vulnerabilities
IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of untrusted data.
Other sources
IBM WebSphere Application Server traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of untrusted data.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server traditional 8.5to a version that resolves this vulnerability.Fixed in 8.5.5.31 - Upgrade
Upgrade
IBM WebSphere Application Server traditional 9.0to a version that resolves this vulnerability.Fixed in 9.0.5.29 - Upgrade
Upgrade
IBM WebSphere Application Server traditionalto a version that resolves this vulnerability.Patch DT496118
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14974?
The severity of CVE-2026-14974 is high, with a CVSS score of 8.1.
How do I fix CVE-2026-14974?
To fix CVE-2026-14974, apply the latest security patches or updates provided by IBM for WebSphere Application Server.
What vulnerabilities are associated with CVE-2026-14974?
CVE-2026-14974 is associated with cross-site scripting and unsafe deserialization vulnerabilities.
Which versions of IBM WebSphere Application Server are affected by CVE-2026-14974?
CVE-2026-14974 affects IBM WebSphere Application Server versions 8.5 and 9.0 traditional.
Can CVE-2026-14974 allow an attacker to execute arbitrary code?
Yes, CVE-2026-14974 can allow a remote attacker to execute arbitrary code due to unsafe deserialization of untrusted data.