CVE-2026-14528 Details
Description
IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain sensitive information.
A vulnerability allowing remote attackers to access sensitive information exists in IBM WebSphere Application Server versions 9.0 and 8.5 traditional. This issue is related to unsafe deserialization, which could lead to unauthorized information exposure.
Users are advised to upgrade to IBM WebSphere Application Server Fix Pack 9.0.5.29 or later, or Fix Pack 8.5.5.31 or later. Interim fixes resolving this vulnerability are also available. Additional interim fixes may be linked from the interim fix download page.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ibm.com/support/pages/node/7281649 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-532 | Insertion of Sensitive Information into Log File | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ibm websphere application server | >= 8.5.0.0, < 8.5.5.31 >= 9.0.0.0, < 9.0.5.29 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 5, 2026 | Initial Analysis | [email protected] |
| Jul 30, 2026 | CVE Modified | CISA-ADP |
| Jul 29, 2026 | CVE Modified | CISA-ADP |
| Jul 28, 2026 | New CVE Received | [email protected] |