CVE Vulnerabilities

CVE-2025-33142

Improper Certificate Validation

Published: Aug 14, 2025 | Modified: Aug 18, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for TLS connections.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

NameVendorStart VersionEnd Version
Websphere_application_serverIbm8.5.0.0 (including)8.5.5.29 (excluding)
Websphere_application_serverIbm9.0.0.0 (including)9.0.5.25 (excluding)

Potential Mitigations

References