CVE-2014-8890: IBM WebSphere Application Server

Medium severity, CVSS 5.1. EPSS: 2.3% chance of exploitation in the next 30 days.

IBM WebSphere Application Server Liberty Profile 8.5.x before 8.5.5.4 allows remote attackers to gain privileges by leveraging the combination of a servlet's deployment descriptor security constraints and ServletSecurity annotations.

Affected products

  • IBM WebSphere Application Server: version 8.5.0.0 only; version 8.5.0.1 only; version 8.5.0.2 only; version 8.5.5.0 only; version 8.5.5.1 only; version 8.5.5.2 only; …

Published 2014-12-18. Last modified 2026-06-17.