Impact
IBM WebSphere Application Server 8.5, 9.0, and Liberty contain an HTTP request smuggling flaw that allows a sender to manipulate the processing of HTTP requests. This weakness can lead to unexpected request handling, potentially exposing data or causing resource misuse. The flaw is catalogued as CWE-444: HTTP Request Smuggling.
Affected Systems
The vulnerability affects IBM CICS TX Advanced 10.1 on Linux as well as IBM WebSphere Application Server 8.5, 9.0, and Liberty products that ship with this component. No other product versions are listed in the CNA data.
Risk and Exploitability
The CVSS score of 4.8 indicates a low impact, while the EPSS score is 0.00177 (i.e., < 1%) and the vulnerability is not listed in CISA KEV, suggesting a very low but non-zero exploitation likelihood. The likely attack vector is remote HTTP traffic; an attacker would need to craft specially formatted requests to exploit the flaw. Given the low severity and lack of widespread exploitation data, operators should treat this as a low-risk issue that merits timely remediation.
OpenCVE Enrichment